logo

CISA tags max severity HPE OneView flaw as actively exploited

ID: 178bfb0a-6dca-542c-9990-a19726f0a32c

STIX ID: report--178bfb0a-6dca-542c-9990-a19726f0a32c

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2026-01-08

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

CISA has flagged CVE-2025-37164, a maximum-severity unauthenticated code-injection vulnerability in HPE OneView (affecting versions before 11.00), as actively exploited in the wild; HPE released patches and CISA added the flaw to its Known Exploited Vulnerabilities catalog, urging immediate upgrades since no mitigations exist.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.