logo

CISA KEV Alert: HPE’s Maximum CVSS Score Flaw and a Zombie PowerPoint Bug

ID: 5747b730-dc68-568e-bb1b-7d845b196ba7

STIX ID: report--5747b730-dc68-568e-bb1b-7d845b196ba7

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-01-08

Date Updated: 2026-04-22

Author: Ddos

...
...

**CISA added two entries to its Known Exploited Vulnerabilities catalog:** a critical unauthenticated remote code execution vulnerability in HPE OneView (CVE-2025-37164, CVSS 10.0) for which HPE has released a hotfix, and a legacy PowerPoint memory-corruption vulnerability (CVE-2009-0556) with evidence of exploitation linked to the Exploit:Win32/Apptom.gen family; FCEB agencies must remediate or disconnect affected systems by January 28, 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.