CVE-2025-37164: Hewlett Packard Enterprise (HPE) OneView Code Injection Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2026-01-07. EPSS: 90.2% chance of exploitation in the next 30 days.

A remote code execution issue exists in HPE OneView.

Affected products

  • HPE OneView: up to and including 10.20.00

Published 2025-12-16. Last modified 2026-06-17.