CISA's list that day

7 January 2026

On CISA added 2 vulnerabilities to its list of exploited vulnerabilities, in Microsoft Office and Hewlett Packard Enterprise (HPE) OneView. US federal agencies must fix them by .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2025-37164Code InjectionHewlett Packard Enterprise (HPE) OneViewPatch this weekMetasploit module; EPSS 0.900.90
CVE-2009-0556PowerPoint Code InjectionMicrosoft OfficePatch this weekEPSS 0.670.67