logo

CISA Urges Emergency Patching for Actively Exploited HPE OneView Flaw

ID: 8096c19e-369b-56c3-8ab7-524841d496f0

STIX ID: report--8096c19e-369b-56c3-8ab7-524841d496f0

Feed Name: HackRead

Threat Score
90/100

Date Published: 2026-01-10

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

A critical unauthenticated remote code execution vulnerability (CVE-2025-37164, CVSS 10.0) in HPE OneView allows attackers to execute arbitrary code via an exposed REST API endpoint; CISA added it to the Known Exploited Vulnerabilities list and HPE recommends immediate updating to OneView 11.00 or later because no workaround exists.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.