CISA's list that day
7 January 2026
On CISA added 2 vulnerabilities to its list of exploited vulnerabilities, in Microsoft Office and Hewlett Packard Enterprise (HPE) OneView. US federal agencies must fix them by .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2025-37164Code Injection | Hewlett Packard Enterprise (HPE) OneView | Patch this weekMetasploit module; EPSS 0.90 | 0.90 | ||
| CVE-2009-0556PowerPoint Code Injection | Microsoft Office | Patch this weekEPSS 0.67 | 0.67 |