CISA Flags Microsoft Office and HPE OneView Bugs as Actively Exploited

Citing evidence of active exploitation, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added two security holes affecting Microsoft Office and Hewlett Packard Enterprise (HPE) OneView to its Known Exploited Vulnerabilities (KEV) database on Wednesday.

Below is a list of the vulnerabilities:

  • CVE-2009-0556 (CVSS score: 8.8) is a code injection vulnerability in Microsoft Office PowerPoint that enables remote attackers to use memory corruption to run arbitrary code.
  • CVE-2025-37164 (CVSS score: 10.0) is a code injection vulnerability in HPW OneView that permits remote code execution by an unauthorized user.

Last month, HPE revealed that CVE-2025-37164 affects all software versions before version 11.00. Additionally, the company released hotfixes for OneView versions 5.20 through 10.

There don’t seem to be any public reports mentioning their exploitation in the wild, and the extent and origin of the attacks aimed at the two vulnerabilities are still unknown read more about CISA Flags Microsoft Office and HPE OneView Bugs as Actively Exploited.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *