Critical Exploitation of Quest KACE SMA Vulnerability Underway
ID: 521cad59-c241-545c-8113-b08e588abb0c
STIX ID: report--521cad59-c241-545c-8113-b08e588abb0c
Feed Name: ThreatCluster
Threat Score
**Executive Summary:** Active exploitation is occurring against CVE-2025-32975 in the Quest KACE Systems Management Appliance (CVSS 10), allowing attackers to bypass authentication, gain administrative access, and harvest credentials; patches were released in June 2025 but many instances remain unpatched, with attacks reported beginning March 9, 2026, and operators continuing their activities—administrators are advised to apply updates and restrict public access to SMA instances.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
