• News/
  • https://www.theregister.com/2026/01/08/cisa_oneview_powerpoint_bugs/

CISA flags exploited Office relic alongside fresh HPE flaw

The Register
·
Carly Page
·
Published Jan 8, 2026
·
Updated

CISA has added a pair of security holes to its actively exploited list, warning that attackers are now abusing a maximum-severity bug in HPE's OneView management software and a years-old flaw in Microsoft Office. The latest update to CISA's Known Exploited Vulnerabilities catalog flags CVE-2025-37164, a code injection vulnerability in HPE OneView, and CVE-2009-0556, a PowerPoint code injection bug that's been lurking for more than 15 years. CVE-2025-37164 carries a perfect 10.0 CVSS score and affects HPE OneView, software used to manage servers, storage, and networking gear from a central console. In a December 18 advisory, HPE said the flaw could be exploited to inject and execute code, potentially granting full control of affected environments, though it did not say at the time whether attacks were already underway. CISA's decision to add the flaw to its exploited-in-the-wild catalog suggests that has now changed, even if details remain thin. HPE did not respond to The Register's questions about whether attackers have been observed in customer environments, how many customers might be exposed, or if any data has been exfiltrated as a result of exploitation. Security firms, however, previously warned that the bug was unlikely to remain theoretical for long. Following HPE's disclosure, a proof-of-concept exploit was published by Rapid7, which suggested defenders treat the issue as an assumed-breach scenario. eSentire noted that the availability of working exploit code signifi...

Read full article

Affected Software

2 affected components
HPE OneView=unknown
Microsoft Office<=unknown
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What vulnerability has CISA added to its actively exploited list?

CISA has added a maximum-severity vulnerability in HPE's OneView management software and a long-standing flaw in Microsoft Office.

2

What does the CISA warning imply for HPE OneView users?

The CISA warning indicates that HPE OneView users are at risk of exploitation due to this critical vulnerability.

3

How long has the Microsoft Office flaw been known?

The Microsoft Office flaw that CISA warned about has been known for several years.

4

What are the potential consequences of the vulnerabilities mentioned in the article?

The vulnerabilities could lead to unauthorized access and exploitation of systems using HPE OneView and Microsoft Office.

5

What organization's security advisory is referenced in the article?

The article references a security advisory from CISA regarding exploited vulnerabilities.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203