Vulnerabilities

Critical HPE OneView Vulnerability Exploited in Attacks

The maximum-severity code injection flaw can be exploited without authentication for remote code execution.

HPE vulnerability

The US cybersecurity agency CISA on Wednesday warned that a critical-severity vulnerability in the OneView product from Hewlett Packard Enterprise (HPE) has been exploited in attacks.

Tracked as CVE-2025-37164 (CVSS score of 10/10), the security defect was disclosed on December 17, 2025, when HPE released hotfixes for it.

HPE credited Nguyen Quoc Khanh for reporting the bug but refrained from sharing technical information.

“This vulnerability could be exploited, allowing a remote unauthenticated user to perform remote code execution,” HPE said.

According to cybersecurity firm Rapid7, the issue likely impacts a specific REST API endpoint reachable without authentication.

On Wednesday, CISA added the flaw to its Known Exploited Vulnerabilities (KEV) catalog, warning that it has been exploited in the wild.

Advertisement. Scroll to continue reading.

“Hewlett Packard Enterprise OneView contains a code injection vulnerability that allows a remote unauthenticated user to perform remote code execution,” the cybersecurity agency notes.

CISA has not shared details on the observed attacks.

On Wednesday, the agency also added to the KEV list a code injection defect in Microsoft Office that was disclosed in 2009.

Tracked as CVE-2009-0556, the bug was exploited in espionage campaigns against the Uyghur ethnic group in China over a decade ago.

Per Binding Operational Directive (BOD) 22-01, federal agencies have three weeks to identify vulnerable HPE OneView and Microsoft Office instances in their environments and patch them.

While BOD 22-01 only applies to federal agencies, all organizations are advised to review CISA’s KEV catalog and apply mitigations and patches for the vulnerabilities in it.

Related: Hackers Exploit Zero-Day in Discontinued D-Link Devices

Related: Fresh MongoDB Vulnerability Exploited in Attacks

Related: WatchGuard Patches Firebox Zero-Day Exploited in the Wild

Related: Vulnerability in Totolink Range Extender Allows Device Takeover

Related Content

Vulnerabilities

The critical-severity path traversal flaw allows unauthenticated attackers to read arbitrary files from the GitLab server.

Vulnerabilities

Tracked as CVE-2026-85102 and CVE-2026-85103, the flaws could be exploited for remote code execution.

Vulnerabilities

A Russian threat actor used AI to build, test, and deploy exploits against hundreds of organizations worldwide.

Vulnerabilities

Tracked as CVE-2026-19490, the authentication bypass flaw has been exploited in the wild since at least September 3.

Vulnerabilities

Cisco and CISA have flagged exploitation of CVE-2026-20079, a vulnerability disclosed in March 2026.

Malware & Threats

The high-severity, unauthenticated vulnerability tracked as CVE-2025-25249 was patched in January 2026.

Mobile & Wireless

The security updates resolve critical flaws across Android’s Framework, System, and Kernel components.

Vulnerabilities

The StyleSmuggler zero-day allows attackers to execute code and deploy a stealthy backdoor on Adobe Commerce and Magento stores.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version