CISA warns of active attacks on HPE OneView and legacy PowerPoint
ID: 073a0226-d38e-5399-8350-5212ba1224da
STIX ID: report--073a0226-d38e-5399-8350-5212ba1224da
Feed Name: Malwarebytes Blog
Threat Score
CISA added two known exploited vulnerabilities to its KEV catalog: CVE-2025-37164, a critical CVSS 10 unauthenticated RCE in HPE OneView (patch released Dec 17, 2025 and a Metasploit PoC published shortly after), and CVE-2009-0556, a legacy PowerPoint remote code execution flaw being reused against outdated Office installs; the alert emphasizes immediate patching and mitigation ahead of CISA enforcement deadlines.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
