CVE-2025-37164
Exploited in the Wild
✓ Confirmed 0-Day
Triaged: March 5, 2026
2 articles
EPSS Score
Source: FIRST.org · 2026-05-24
75.28%
probability
This CVE has a 75.28% probability
of being exploited in the next 30 days.
0%
Top 98.9th percentile of all CVEs
100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE.
View on VulnerabilityLookup ↗
Attack Intelligence
Exploits & PoC
g0vguy/CVE-2025-37164-PoC
PoC for CVE-2025-37164
6
LACHHAB-Anas/Exploit_CVE-2025-37164
Exploit for the CVE-2025-37164
1
2 repos — triés par ⭐
Rechercher sur GitHub ↗
CISA Flags Microsoft Office and HPE OneView Bugs as Actively Exploited
TheHackerNews
Jan 08, 2026
HPE OneView Flaw Rated CVSS 10.0 Allows Unauthenticated Remote Code Execution
TheHackerNews
Dec 18, 2025
Signal Intelligence
Confidence
85%
EPSS
75.28%
Mentions
2
Last Seen
Jan 08, 2026
CNA Information
Analyst Note
CVE-2025-37164 is explicitly named in CISA KEV catalog as actively exploited in the wild (per TheHackerNews article [1]). Published December 16, 2025, with concurrent evidence of active exploitation and patch availability. CVSS 10.0 severity and RCE nature confirm criticality. Not in Project Zero but CISA KEV listing provides authoritative confirmation of zero-day exploitation.
Threat Actors 8
APT 28
apt_group
Information theft and espionage
🇷🇺 RU
Hacking Team
apt_group
🇮🇹 IT
Tick
apt_group
Information theft and espionage
🇨🇳 CN
TAG-28
apt_group
Information theft and espionage
🇨🇳 CN
Roaming Tiger
apt_group
Information theft and espionage
🇨🇳 CN
White Bear
apt_group
Information theft and espionage
🇷🇺 RU
Mana Team
apt_group
🇨🇳 CN
Lurk
apt_group
Financial crime
🇷🇺 RU
Triage Info
Decided atMar 05, 2026