CISA KEV Alert: HPE’s Maximum CVSS Score Flaw and a Zombie PowerPoint Bug
ID: 5747b730-dc68-568e-bb1b-7d845b196ba7
STIX ID: report--5747b730-dc68-568e-bb1b-7d845b196ba7
Feed Name: securityonline.info
Threat Score
**CISA added two entries to its Known Exploited Vulnerabilities catalog:** a critical unauthenticated remote code execution vulnerability in HPE OneView (CVE-2025-37164, CVSS 10.0) for which HPE has released a hotfix, and a legacy PowerPoint memory-corruption vulnerability (CVE-2009-0556) with evidence of exploitation linked to the Exploit:Win32/Apptom.gen family; FCEB agencies must remediate or disconnect affected systems by January 28, 2026.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
