HPE OneView CVE-2025-37164 patch release
Security Patch Release
Summary
Hide ▲
Show ▼
Hewlett Packard Enterprise released version 11.00 to fix CVE-2025-37164, a CVSS 10.0 flaw in HPE OneView Software that could allow remote code execution. HPE also provided hotfixes for versions 5.20 through 10.20, giving administrators a clear remediation path for affected deployments. The vendor said the update covers all versions prior to 11.00, making the release the primary fix for the issue.
Cases
Related Happenings
Ivanti security patch release for CVE-2026-8043
Security Patch Release
First: 18.05.2026 13:54
Last: 18.05.2026 13:54
Sources 1
About this happening:
**Ivanti, Fortinet, SAP, Broadcom, and n8n** released **security fixes** on **2026-05-18** for flaws that could enable **authentication bypass**, **remote code execution**, **SQL...
Ivanti security patch release for CVE-2026-8043
Security Patch ReleaseAbout this happening: **Ivanti, Fortinet, SAP, Broadcom, and n8n** released **security fixes** on **2026-05-18** for flaws that could enable **authentication bypass**, **remote code execution**, **SQL...
GIGABYTE security patch release for CVE-2026-4415
Security Patch Release
First: 01.04.2026 01:28
Last: 01.04.2026 01:28
Sources 1
About this happening:
**GIGABYTE** is directing users of **Control Center** to upgrade to **25.12.10.01** to mitigate **CVE-2026-4415**, a flaw that exposed systems to remote file writes. The update ma...
GIGABYTE security patch release for CVE-2026-4415
Security Patch ReleaseAbout this happening: **GIGABYTE** is directing users of **Control Center** to upgrade to **25.12.10.01** to mitigate **CVE-2026-4415**, a flaw that exposed systems to remote file writes. The update ma...
TP-Link security patch release for CVE-2025-15517
Security Patch Release
First: 25.03.2026 13:11
Last: 25.03.2026 13:11
Sources 1
About this happening:
**TP-Link** released **security updates** for its **Archer NX** router series to close a critical authentication-bypass flaw that could let attackers upload firmware without loggi...
TP-Link security patch release for CVE-2025-15517
Security Patch ReleaseAbout this happening: **TP-Link** released **security updates** for its **Archer NX** router series to close a critical authentication-bypass flaw that could let attackers upload firmware without loggi...
Hewlett Packard Enterprise (HPE) security patch release for CVE-2026-23813
Security Patch Release
First: 10.03.2026 19:30
Last: 10.03.2026 19:30
Sources 1
About this happening:
**HPE** released **security updates** for **Aruba Networking AOS-CX**, closing **multiple vulnerabilities** including authentication and code execution issues on **CX-series campu...
Hewlett Packard Enterprise (HPE) security patch release for CVE-2026-23813
Security Patch ReleaseAbout this happening: **HPE** released **security updates** for **Aruba Networking AOS-CX**, closing **multiple vulnerabilities** including authentication and code execution issues on **CX-series campu...
Microsoft security patch release for CVE-2026-20805
Security Patch Release
First: 14.01.2026 02:47
Last: 14.01.2026 02:47
Sources 1
About this happening:
**Microsoft** released January 2026 security updates for **Windows** and supported software, fixing **at least 113 vulnerabilities** and **8 critical flaws**. The release includes...
Microsoft security patch release for CVE-2026-20805
Security Patch ReleaseAbout this happening: **Microsoft** released January 2026 security updates for **Windows** and supported software, fixing **at least 113 vulnerabilities** and **8 critical flaws**. The release includes...
Timeline
-
18.12.2025 16:39 2 articles · 5mo ago
HPE releases OneView 11.00 and hotfixes for CVE-2025-37164
Mitigation Patch UpdateHewlett Packard Enterprise resolved CVE-2025-37164 in HPE OneView Software, a maximum-severity flaw with CVSS 10.0 that could allow a remote unauthenticated user to perform remote code execution, and made available a hotfix for OneView versions 5.20 through 10.20 along with separate hotfixes for the OneView virtual appliance and Synergy Composer2.
Show sources
- HPE OneView Flaw Rated CVSS 10.0 Allows Unauthenticated Remote Code Execution — thehackernews.com — 18.12.2025 16:39
- HPE OneView Flaw Rated CVSS 10.0 Allows Unauthenticated Remote Code Execution — thehackernews.com — 18.12.2025 16:39