By Carly Page
Publication Date: 2026-01-08 13:44:00
CISA has added a pair of security holes to its actively exploited list, warning that attackers are now abusing a high-severity bug in HPE’s OneView management software and a years-old flaw in Microsoft Office.
The latest update of CISA Catalog of Known Exploited Vulnerabilities points out CVE-2025-37164, a code injection vulnerability in HPE OneView, and CVE-2009-0556, a PowerPoint code injection bug that has been lurking for more than 15 years.
CVE-2025-37164 has a perfect CVSS score of 10.0 and affects HPE OneView, the software used to manage servers, storage, and network equipment from a central console. In a December 18 notice, HPE saying The flaw could be exploited to inject and execute code, potentially granting full control of affected environments. although he did not say at the time whether the attacks were already underway.
CISA’s decision to add the bug to its catalog of exploited in the wild suggests that now…

