Cybersecurity News and Headlines
  • All Technology
  • AI
  • Autonomy
  • B2B Growth
  • Big Data
  • BioTech
  • ClimateTech
  • Consumer Tech
  • Crypto
  • Cybersecurity
  • DevOps
  • Digital Marketing
  • Ecommerce
  • EdTech
  • Enterprise
  • FinTech
  • GovTech
  • Hardware
  • HealthTech
  • HRTech
  • LegalTech
  • Nanotech
  • PropTech
  • Quantum
  • Robotics
  • SaaS
  • SpaceTech
AllNewsDealsSocialBlogsVideosPodcastsDigests

Cybersecurity Pulse

EMAIL DIGESTS

Daily

Every morning

Weekly

Sunday recap

NewsDealsSocialBlogsVideosPodcasts
CybersecurityNewsCISA Warns of Attacks on PowerPoint and HPE Vulnerabilities
CISA Warns of Attacks on PowerPoint and HPE Vulnerabilities
Cybersecurity

CISA Warns of Attacks on PowerPoint and HPE Vulnerabilities

•January 8, 2026
0
The Cyber Express
The Cyber Express•Jan 8, 2026

Companies Mentioned

Hewlett Packard Enterprise

Hewlett Packard Enterprise

HPE

Microsoft

Microsoft

MSFT

Rapid7

Rapid7

RPD

Why It Matters

The inclusion underscores that both legacy office software and modern data‑center tools are still attractive targets, forcing enterprises to accelerate patch cycles and reassess asset inventories.

Key Takeaways

  • •CISA adds HPE and PowerPoint flaws to 2026 KEV list.
  • •HPE OneView CVE‑2025‑37164 enables unauthenticated remote code execution.
  • •PowerPoint CVE‑2009‑0556 exploited since 2009, still unpatched on legacy systems.
  • •Rapid7 released PoC and Metasploit module for HPE vulnerability.
  • •Enterprises must apply HPE hotfixes and retire vulnerable PowerPoint versions.

Pulse Analysis

The Cybersecurity and Infrastructure Security Agency (CISA) maintains the Known Exploited Vulnerabilities (KEV) catalog to flag flaws that adversaries are actively weaponizing. Adding older bugs like the 2009 PowerPoint issue alongside brand‑new high‑severity flaws reflects a broader trend: threat actors continue to mine legacy code for easy entry points, while modern infrastructure platforms present lucrative, high‑impact targets. By publishing the KEV list, CISA provides a prioritized roadmap for IT teams, helping them focus limited resources on vulnerabilities most likely to be leveraged in the wild.

HPE OneView’s CVE‑2025‑37164 exemplifies the danger of unpatched code in critical data‑center management stacks. Rated a perfect 10.0, the vulnerability permits unauthenticated remote code execution, and Rapid7’s proof‑of‑concept demonstrates a straightforward exploitation path. The vendor’s advisory recommends a hotfix covering versions 5.20 through 10.20, yet the Rapid7 analysis suggests that only specific OneView for VMs releases may be vulnerable. Organizations running HPE OneView should verify their version, apply the patch immediately, and monitor for any Metasploit‑based activity, as the public module lowers the barrier for less‑skilled attackers.

The PowerPoint CVE‑2009‑0556 case serves as a cautionary tale for legacy software stewardship. Although Microsoft issued a fix in 2009, many enterprises still host archived Office installations for compatibility, leaving them exposed to a memory‑corruption exploit that can grant full system control. The vulnerability’s continued presence in the KEV catalog signals that attackers still target outdated office suites, especially in environments with privileged users. Companies should decommission unsupported PowerPoint versions, enforce least‑privilege policies, and ensure that any residual files are scanned for malicious payloads. Together, these incidents highlight the need for continuous vulnerability management across both new and legacy technology stacks.

CISA Warns of Attacks on PowerPoint and HPE Vulnerabilities

Read Original Article
0

Comments

Want to join the conversation?

Loading comments...