The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two critical vulnerabilities—one in HPE OneView (CVE-2025-37164) and another in Microsoft Office PowerPoint (CVE-2009-0556)—to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The HPE OneView flaw, with a maximum CVSS score of 10.0, allows unauthenticated remote code execution on all versions prior to 11.00, and HPE has released patches and hotfixes for affected versions. The PowerPoint vulnerability, rated CVSS 8.8, enables remote code execution via memory corruption, and both flaws are considered significant risks due to the availability of proof-of-concept exploit code and ongoing exploitation in the wild.
CISA has mandated that Federal Civilian Executive Branch (FCEB) agencies apply the necessary patches by January 28, 2026, under Binding Operational Directive 22-01, and strongly encourages all organizations to update their systems immediately. There are no workarounds for the HPE OneView vulnerability, making prompt patching essential. The public release of exploit code for CVE-2025-37164 has heightened the urgency, and organizations are advised to follow vendor instructions or discontinue use of affected products if mitigations are unavailable. Both vulnerabilities are being actively targeted and pose significant risks to enterprise environments if left unaddressed.

See which actors are running it and whether you're in range.
5 events from the most recent confirmed update back to the earliest known activity.
Following the KEV additions, CISA required FCEB agencies to apply fixes or mitigations for the HPE OneView and PowerPoint vulnerabilities by January 28, 2026. Private-sector organizations were also urged to patch promptly because no effective workaround was available for the HPE flaw.
CISA added CVE-2025-37164 in HPE OneView and CVE-2009-0556 in Microsoft Office PowerPoint to its Known Exploited Vulnerabilities catalog, confirming active exploitation. The agency directed Federal Civilian Executive Branch agencies to remediate the issues under Binding Operational Directive 22-01.
Detailed public exploit code for CVE-2025-37164 was released, with reports citing a PoC on December 23, 2025 and later references to a Metasploit module. The publication of exploit tooling increased the likelihood of real-world attacks against exposed OneView instances.
Hewlett Packard Enterprise released hotfixes for CVE-2025-37164, a critical unauthenticated remote code execution/code injection flaw affecting OneView versions prior to 11.00. Multiple reports place the patch release on December 16, 2025, with upgrades to version 11.00 or later recommended.
Microsoft addressed CVE-2009-0556, a memory-corruption/code-execution flaw in PowerPoint that could be triggered with a crafted .ppt file. Despite being patched in 2009, the vulnerability continued to affect unpatched or unsupported systems.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
9 references tracked. Mallory keeps watching after this page renders.
go.theregister.com
Open sourcethehackernews.com
Open sourcebleepingcomputer.com
Open sourcesecurityaffairs.com
Open sourcecybersecuritynews.com
Open sourcemalwarebytes.com
Open sourcehelpnetsecurity.com
Open sourcesecurityonline.info
Open sourcethecyberexpress.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.