A critical HPE OneView flaw is being exploited in the wild – here’s everything we know so far

A critical HPE OneView flaw is being exploited in the wild – here’s everything we know so far

By Emma Woollacott
Publication Date: 2026-01-09 11:31:00

He US Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about an HPE OneView maximum severity vulnerability that is being actively exploited in the wild.

Track as CVE-2025-37164This is a code injection vulnerability within an insecure REST API endpoint, the security agency noted, allowing an unauthenticated remote user to perform remote code execution.