惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

MyScale Blog
MyScale Blog
J
Java Code Geeks
Vercel News
Vercel News
A
About on SuperTechFans
G
Google Developers Blog
C
Check Point Blog
腾讯CDC
N
Netflix TechBlog - Medium
博客园 - 司徒正美
S
SegmentFault 最新的问题
D
DataBreaches.Net
博客园_首页
美团技术团队
Stack Overflow Blog
Stack Overflow Blog
博客园 - 聂微东
量子位
雷峰网
雷峰网
IT之家
IT之家
小众软件
小众软件
Blog — PlanetScale
Blog — PlanetScale
博客园 - 三生石上(FineUI控件)
H
Help Net Security
宝玉的分享
宝玉的分享
博客园 - 叶小钗

The Register - Security: Patches

Homeland security cybercops say patch TrueConf (Russia Microsoft Defender for Endpoint leaves some Linux boxes defenseless after update Year-long Russian attacks infect users as soon as they look at an email Cisco SD-WAN make-me-root bug under attack Ivanti tells Sentry customers to patch now as critical bugs hit 10.0 and 9.9 AI is making Patch Tuesday (kinda) fun again Anthropic to release Mythos-class models to the public Clear your calendar, Drupal user: You have a critically urgent patch to install Welcome to the vulnpocalypse, as vendors use AI to find bugs and patches multiply like rabbits Doozy of a Patch Tuesday includes 30 critical Microsoft CVEs Critical cPanel, WHM flaw probs exploited as 0-day, pros say Microsoft patch fell short. New Windows flaw exploited More Cisco SD-WAN bugs battered in attacks Critical Fortinet sandbox bugs allow auth bypass and RCE Ancient Excel bug comes out of retirement for active attacks Microsoft's massive Patch Tuesday: It's raining bugs Ransomware scum, other crims exploit 4 old Microsoft bugs Attackers exploited the FortiClient EMS bug as a 0-day Citrix NetScaler bug may be multiple flaws in one Ransomware crims abused Cisco 0-day weeks before disclosure Google rushes Chrome update to fix zero-days under attack CISA warns max-severity n8n bug is being exploited in the wild Cisco warns of two more SD-WAN bugs under active attack LexisNexis Legal & Professional confirms data breach Five Eyes warn: Patch your Cisco SD-WAN or risk root takeover Patch these 4 critical, make-me-root SolarWinds bugs ASAP Attacker gets into France's DB listing all bank accounts CISA gives feds 3 days to patch actively exploited Dell bug CISA gives feds 3 days to patch actively exploited Dell bug Google fixes exploited Chrome CSS zero-day
CISA flags exploited Office relic alongside fresh HPE flaw
Carly Page Carly Page · 2026-01-08 · via The Register - Security: Patches

Cyber-crime

Max-severity OneView hole joins a PowerPoint bug that should've been retired years ago

CISA has added a pair of security holes to its actively exploited list, warning that attackers are now abusing a maximum-severity bug in HPE's OneView management software and a years-old flaw in Microsoft Office.

The latest update to CISA's Known Exploited Vulnerabilities catalog flags CVE-2025-37164, a code injection vulnerability in HPE OneView, and CVE-2009-0556, a PowerPoint code injection bug that's been lurking for more than 15 years.

CVE-2025-37164 carries a perfect 10.0 CVSS score and affects HPE OneView, software used to manage servers, storage, and networking gear from a central console. In a December 18 advisory, HPE said the flaw could be exploited to inject and execute code, potentially granting full control of affected environments, though it did not say at the time whether attacks were already underway.

CISA's decision to add the flaw to its exploited-in-the-wild catalog suggests that has now changed, even if details remain thin. HPE did not respond to The Register's questions about whether attackers have been observed in customer environments, how many customers might be exposed, or if any data has been exfiltrated as a result of exploitation.

Security firms, however, previously warned that the bug was unlikely to remain theoretical for long. Following HPE's disclosure, a proof-of-concept exploit was published by Rapid7, which suggested defenders treat the issue as an assumed-breach scenario. eSentire noted that the availability of working exploit code significantly lowered the barrier for attackers to move from curiosity to compromise.

A spokesperson for HPE told us: "HPE was alerted to this potential vulnerability by a community member and worked quickly to release a hotfix on December 17. While we have not received reports from customers of the vulnerability being exploited, it is important that OneView users apply the patch as soon as possible."

Alongside the OneView issue, CISA also flagged CVE-2009-0556, a Microsoft Office PowerPoint code injection vulnerability rated 8.8 on the CVSS scale. The bug, confirmed by Microsoft back in 2009, allows remote attackers to execute arbitrary code via memory corruption when a user opens a specially crafted PowerPoint file. Microsoft patched the issue years ago as part of MS09-017, but its appearance in the KEV catalog indicates that unpatched or unsupported systems are still being successfully targeted.

The two vulnerabilities have little in common. One is old enough to vote and should have been patched out of existence long ago, while the other is a fresh enterprise flaw buried in the machinery of modern datacenters. For attackers, age clearly isn't a deal-breaker if the exploit still works. ®