logo

CISA Warns of Attacks on PowerPoint and HPE Vulnerabilities

ID: 68e6800e-7249-552b-af73-709a073fa78d

STIX ID: report--68e6800e-7249-552b-af73-709a073fa78d

Feed Name: The Cyber Express

Threat Score
75/100

Date Published: 2026-01-08

Date Updated: 2026-04-23

Author: Paul Shread

...
...

CISA added two vulnerabilities to its KEV catalog: CVE-2025-37164, a critical (10.0) remote code execution flaw in HPE OneView for which Rapid7 published a PoC and a Metasploit module and HPE has released a hotfix, and CVE-2009-0556, an older PowerPoint RCE first exploited in 2009; the HPE issue poses immediate risk due to public exploit code while the PowerPoint flaw primarily impacts legacy products.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.