HomeSecurityCISA: Microsoft Office and HPE OneView Vulnerabilities in the KEV List

CISA: Microsoft Office and HPE OneView vulnerabilities in the KEV Catalog

The United States Cybersecurity and Infrastructure Security Agency (CISA) has added two security vulnerabilities in Microsoft Office and Hewlett Packard Enterprise (HPE) OneView to its list of Known Exploitable Vulnerabilities (KEV).

See also: PoC exploit for CVE-2025-38352 vulnerability in Android/Linux kernel

CISA Microsoft Office HPE OneView

The two vulnerabilities that were added to the CISA KEV List

CVE-2009-0556 (CVSS score: 8.8) is a code injection in Microsoft Office PowerPoint vulnerability that allows remote attackers to execute arbitrary code via memory corruption.

CVE-2025-37164 (CVSS score: 10.0) is a code injection vulnerability in HPE OneView that allows a remote unauthorized user to perform remote code execution .

Details about CVE-2025-37164 emerged last month when HPE said the vulnerability affects all versions of the software prior to version 11.00. The company also made hotfixes available for OneView versions 5.20 through 10.

The scope of the attacks and the actors targeting the two vulnerabilities are currently unclear, and there appear to be no public reports of their exploitation. However, a report from eSentire on December 23, 2025, revealed the release of a detailed PoC exploit for CVE-2025-37164.

See also: Veeam: New vulnerabilities expose backup servers to RCE attacks

CISA: Microsoft Office and HPE OneView vulnerabilities in the KEV Catalog

“The public availability of a PoC exploit significantly increases the risk to organizations running affected versions of the application,” eSentire said. “Since the vulnerability affects all versions prior to 11.0, organizations are urged to apply the required updates to mitigate the potential risk of exploitation.”

Federal agencies are required to implement the necessary fixes by January 28, 2026, to protect their networks from active threats.

The importance of immediate action cannot be underestimated, as exploiting these vulnerabilities can lead to significant security breaches and data loss. Organizations must ensure their infrastructure is up-to-date and protected by applying the latest security patches and continuously monitoring threats.

See also: Vulnerability in TOTOLINK EX200 allows full system access

CISA: Microsoft Office and HPE OneView vulnerabilities in the KEV Catalog

CISA continues to closely monitor the situation and provide guidance and support to organizations in addressing these critical security issues. Collaboration with cybersecurity and sharing information is vital to effectively address these threats and protect critical infrastructure from malicious attacks.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS