logo

Maximum Severity HPE OneView Flaw Exploited in the Wild

ID: 8406f545-f9ae-56ae-92a9-33257099c11c

STIX ID: report--8406f545-f9ae-56ae-92a9-33257099c11c

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2026-01-08

Date Updated: 2026-04-21

Author: Rob Wright

...
...

A critical unauthenticated remote code execution vulnerability (CVE-2025-37164, CVSS 10) affecting HPE OneView — an infrastructure management/control-plane product — was disclosed and patched (hotfixes for versions 5.20 through 10.20). CISA added the flaw to its Known Exploited Vulnerabilities catalog and reported it has come under attack, though HPE and Rapid7 state there are no confirmed customer exploitation reports; defenders are advised to treat it as an assumed-breach scenario and apply patches immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.