The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has flagged a maximum-severity HPE OneView vulnerability as actively exploited in attacks. HPE's OneView infrastructure management software helps IT admins automate the management of storage, servers, and networking devices from a centralized interface. Tracked as CVE-2025-37164, this critical security flaw was reported by Vietnamese security researcher Nguyen Quoc Khanh (brocked200) to HPE, which released security patches in mid-December. CVE-2025-37164 affects all OneView versions released before v11.00 and can be exploited by unauthenticated threat actors through low-complexity code-injection attacks to gain remote code execution on unpatched systems. "A potential security vulnerability has been identified in Hewlett Packard Enterprise OneView Software. This vulnerability could be exploited, allowing a remote unauthenticated user to perform remote code execution," HPE warned on December 16. There are no workarounds or mitigations for CVE-2025-37164, so HPE advised customers to upgrade to OneView version 11.00 or later (available through HPE's Software Center) as soon as possible. CISA has also added the vulnerability to its catalog of flaws exploited in the wild, giving Federal Civilian Executive Branch (FCEB) agencies three weeks to secure their systems by January 28th, as mandated by the Binding Operational Directive (BOD) 22-01 issued in November 2021. Even though BOD 22-01 targets only federal agencies, ...
CISA tags max severity HPE OneView flaw as actively exploited
BleepingComputer
·Sergiu Gatlan
·Published Jan 8, 2026
·Updated
Affected Software
1 affected component
Hewlett Packard Enterprise OneView<11.00
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a critical vulnerability in HPE OneView that is being actively exploited according to CISA.
2
What security implications are discussed in the article?
The article outlines that the HPE OneView flaw has been deemed maximum severity and is currently being exploited in cyber attacks.
3
What products or software are affected?
The affected software mentioned in the article is HPE OneView, specifically versions up to 11.00.
4
Who has issued a warning about the HPE OneView vulnerability?
The warning about the HPE OneView vulnerability has been issued by the U.S. Cybersecurity and Infrastructure Security Agency (CISA).
5
What actions should users of HPE OneView take in response to this vulnerability?
Users of HPE OneView should prioritize updating to secure versions and implement necessary security measures to protect their systems.