LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-37164: Hewlett Packard Enterprise (HPE) OneView Code Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jan 7, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jan 28, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-37164 to its Known Exploited Vulnerabilities catalog on Jan 7, 2026, with a federal patch deadline of Jan 28, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Hewlett Packard Enterprise (HPE) OneView contains a code injection vulnerability that allows a remote unauthenticated user to perform remote code execution.

HPE OneView contains a code injection vulnerability that permits remote unauthenticated attackers to execute arbitrary code on affected systems. This weakness can lead to complete compromise of the management platform without requiring valid credentials. Organizations using HPE OneView for infrastructure management should treat this as a high-priority issue because successful exploitation grants attackers control over server and storage resources managed by the product.

How it works

The vulnerability is classified under CWE-94, improper control of generation of code. An attacker supplies input that the application treats as executable instructions rather than data.

Am I affected? How to find it in your systems

HPE OneView is typically deployed as a physical or virtual appliance that manages HPE server, storage, and networking hardware in data centers and private clouds. Begin by locating all instances through asset inventories, hypervisor listings, and network scans for management interfaces.

Confirm the precise versions and configuration details against the vendor advisory, as impact depends on those specifics. Examine web-access and application logs for unexpected unauthenticated requests to OneView endpoints; repeated or anomalous patterns may indicate reconnaissance or exploitation attempts.

How to remediate

Apply the software update referenced in the vendor advisory. This addresses the code-injection flaw directly and should be performed on every affected instance.

If you can't patch immediately

Implement mitigations exactly as described in the vendor instructions. Where OneView is used as a cloud service, follow applicable BOD 22-01 guidance. If suitable mitigations cannot be applied, discontinue use of the product until remediation is possible.

If your data may have been exposed

Remote code execution vulnerabilities have resulted in unauthorized access and subsequent data exposure in comparable management platforms. Organizations can run a free exposure scan of their email addresses to check against known breach data.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedHewlett Packard Enterprise (HPE) · OneView
WeaknessCWE-94
Added to CISA KEVJan 7, 2026
Federal patch deadlineJan 28, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities