logo

CVSS 10 Alert: Quest KACE SMA Auth Bypass Exploited to Hijack Managed Endpoints

ID: 024692c5-de4b-53b1-ac0d-a61eb577fb3e

STIX ID: report--024692c5-de4b-53b1-ac0d-a61eb577fb3e

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-05-16

Date Updated: 2026-05-16

Author: Ddos

...
...

A critical authentication-bypass vulnerability in the Quest KACE Systems Management Appliance (CVE-2025-32975, CVSS 10.0) has been actively exploited since March 2026; over 12,000 internet-facing appliances remain vulnerable. Researchers tied a major compromise of MSP HIQ to the flaw, revealing exfiltrated account data for 60 client organizations, attacker toolkits (persistence via local kace_admin account, AD reconnaissance PowerShell, custom SOCKS5 tunneling), and a publicly exposed C2 infrastructure (notably 216.126.225.156). Immediate remediation guidance includes patching to specified secure builds, hunting for the kace_admin account, and blocking the identified C2 IP.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.