CVSS 10 Alert: Quest KACE SMA Auth Bypass Exploited to Hijack Managed Endpoints
ID: 024692c5-de4b-53b1-ac0d-a61eb577fb3e
STIX ID: report--024692c5-de4b-53b1-ac0d-a61eb577fb3e
Feed Name: securityonline.info
A critical authentication-bypass vulnerability in the Quest KACE Systems Management Appliance (CVE-2025-32975, CVSS 10.0) has been actively exploited since March 2026; over 12,000 internet-facing appliances remain vulnerable. Researchers tied a major compromise of MSP HIQ to the flaw, revealing exfiltrated account data for 60 client organizations, attacker toolkits (persistence via local kace_admin account, AD reconnaissance PowerShell, custom SOCKS5 tunneling), and a publicly exposed C2 infrastructure (notably 216.126.225.156). Immediate remediation guidance includes patching to specified secure builds, hunting for the kace_admin account, and blocking the identified C2 IP.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
