HPE OneView actively exploited remote code execution flaw (CVE-2025-37164)
Vulnerability
Summary
Hide ▲
Show ▼
CVE-2025-37164 in HPE OneView is being actively exploited, with Check Point Research reporting a Linux-based RondoDox botnet campaign that escalated in January 2026 after early probing in December 2025. The firm recorded more than 40,000 attack attempts on 7 January between 05:45 and 09:20 UTC and said the activity was automated, botnet-driven exploitation. The flaw is a critical RCE in the exposed ExecuteCommand REST API endpoint, and CISA added it to the KEV catalog.
Cases
Related Happenings
CPanel & WHM authentication-bypass exploitation wave (CVE-2026-41940)
Exploitation Wave
First: 04.05.2026 11:25
Last: 04.05.2026 11:25
Sources 1
About this happening:
Active exploitation of **CVE-2026-41940** is driving a **large cPanel & WHM compromise wave**, putting exposed servers at risk of administrative takeover. **More than 40,000 serve...
CPanel & WHM authentication-bypass exploitation wave (CVE-2026-41940)
Exploitation WaveAbout this happening: Active exploitation of **CVE-2026-41940** is driving a **large cPanel & WHM compromise wave**, putting exposed servers at risk of administrative takeover. **More than 40,000 serve...
Mirai-based CVE-2025-29635 D-Link DIR-823X botnet-enlistment campaign
Campaign
First: 22.04.2026 23:04
Last: 22.04.2026 23:04
Sources 1
About this happening:
The **Mirai-based malware campaign** is **actively exploiting CVE-2025-29635** against **D-Link DIR-823X routers**, turning vulnerable devices into botnet nodes. The activity matt...
Mirai-based CVE-2025-29635 D-Link DIR-823X botnet-enlistment campaign
CampaignAbout this happening: The **Mirai-based malware campaign** is **actively exploiting CVE-2025-29635** against **D-Link DIR-823X routers**, turning vulnerable devices into botnet nodes. The activity matt...
F5 BIG-IP APM active exploitation wave (CVE-2025-53521)
Exploitation Wave
First: 02.04.2026 11:25
Last: 02.04.2026 11:25
Sources 1
About this happening:
As of **2026-04-02**, ongoing attacks are exploiting **CVE-2025-53521** against **F5 BIG-IP APM** systems, leaving more than **14,000** exposed online and at risk of remote code e...
F5 BIG-IP APM active exploitation wave (CVE-2025-53521)
Exploitation WaveAbout this happening: As of **2026-04-02**, ongoing attacks are exploiting **CVE-2025-53521** against **F5 BIG-IP APM** systems, leaving more than **14,000** exposed online and at risk of remote code e...
Oracle WebLogic Server CVE-2026-21962 rapid exploitation wave
Exploitation Wave
First: 26.03.2026 18:00
Last: 26.03.2026 18:00
Sources 1
About this happening:
**Oracle WebLogic Server** systems faced a rapid **CVE-2026-21962** exploitation wave after public exploit code appeared, creating immediate **RCE risk** for exposed servers. The...
Oracle WebLogic Server CVE-2026-21962 rapid exploitation wave
Exploitation WaveAbout this happening: **Oracle WebLogic Server** systems faced a rapid **CVE-2026-21962** exploitation wave after public exploit code appeared, creating immediate **RCE risk** for exposed servers. The...
Langflow CVE-2026-33017 exploitation wave
Exploitation Wave
First: 20.03.2026 12:20
Last: 20.03.2026 12:20
Sources 1
About this happening:
**CVE-2026-33017** in **Langflow** is being exploited in a fast-moving **early wave** that surfaced within **20 hours** of the advisory, putting exposed instances at immediate ris...
Langflow CVE-2026-33017 exploitation wave
Exploitation WaveAbout this happening: **CVE-2026-33017** in **Langflow** is being exploited in a fast-moving **early wave** that surfaced within **20 hours** of the advisory, putting exposed instances at immediate ris...
Timeline
-
08.01.2026 09:45 3 articles · 4mo ago
HPE warns on December 16 about OneView RCE and advises upgrading
Mitigation Patch UpdateHPE warns on December 16 that CVE-2025-37164 in HPE OneView could let a remote unauthenticated user achieve remote code execution, says all OneView versions released before v11.00 are affected, and advises customers to upgrade to OneView version 11.00 or later because no workarounds or mitigations are available.
Show sources
- CISA tags max severity HPE OneView flaw as actively exploited — www.bleepingcomputer.com — 08.01.2026 09:45
- RondoDox Botnet Targets HPE OneView Vulnerability in Exploitation Wave — www.infosecurity-magazine.com — 16.01.2026 11:15
- HPE OneView Flaw Rated CVSS 10.0 Allows Unauthenticated Remote Code Execution — thehackernews.com — 18.12.2025 16:39
-
08.01.2026 09:45 2 articles · 4mo ago
CISA flags CVE-2025-37164 in HPE OneView as actively exploited
Initial DisclosureCISA flags CVE-2025-37164 in HPE OneView as actively exploited, adds the flaw to its catalog of vulnerabilities exploited in the wild, and gives Federal Civilian Executive Branch agencies three weeks to secure affected systems by January 28 under BOD 22-01 while urging other organizations to patch or discontinue use if mitigations are unavailable.
Show sources
- CISA tags max severity HPE OneView flaw as actively exploited — www.bleepingcomputer.com — 08.01.2026 09:45
- CISA tags max severity HPE OneView flaw as actively exploited — www.bleepingcomputer.com — 08.01.2026 09:45