Article Details

Scrape Timestamp (UTC): 2026-01-08 04:54:14.176

Source: https://thehackernews.com/2026/01/cisa-flags-microsoft-office-and-hpe.html

Original Article Text

Click to Toggle View

CISA Flags Microsoft Office and HPE OneView Bugs as Actively Exploited. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added two security flaws impacting Microsoft Office and Hewlett Packard Enterprise (HPE) OneView to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabilities are listed below - Details of CVE-2025-37164 emerged last month when HPE said the vulnerability impacts all versions of the software prior to version 11.00. The company also made available hotfixes for OneView versions 5.20 through 10. The scope and source of the attacks targeting the two flaws is presently unclear, and there appear to be no public reports referencing their exploitation in the wild. However, a report from eSentire on December 23, 2025, revealed the release of a detailed proof-of-concept (PoC) exploit for CVE-2025-37164. "Public availability of PoC exploit code significantly increases the risk to organizations running affected versions of the application," eSentire said. "As the vulnerability impacts all versions prior to 11.0, organizations are strongly advised to apply the required updates to mitigate the potential risk of exploitation." Pursuant to Binding Operational Directive (BOD) 22-01, Federal Civilian Executive Branch (FCEB) agencies are recommended to apply the necessary fixes by January 28, 2026, to secure their networks against active threats.

Daily Brief Summary

VULNERABILITIES // CISA Alerts on Active Exploitation of Microsoft Office, HPE OneView Flaws

CISA has added vulnerabilities in Microsoft Office and HPE OneView to its Known Exploited Vulnerabilities catalog, indicating active exploitation risks.

The HPE OneView flaw, CVE-2025-37164, affects all software versions before 11.00, with hotfixes available for versions 5.20 through 10.

eSentire reported a proof-of-concept exploit for CVE-2025-37164, raising the threat level for organizations using older software versions.

The exact scope and origin of attacks exploiting these vulnerabilities remain unclear, with no public exploitation reports currently available.

Federal Civilian Executive Branch agencies are urged to implement updates by January 28, 2026, as per Binding Operational Directive 22-01.

Organizations are advised to prioritize patching to mitigate potential exploitation risks and secure their networks against these active threats.