logo

Warning: CRITICAL Vulnerabilities found in Quest KACE Systems Management Appliance! Patch Immediately!

ID: 985fa13a-35e2-5505-af7b-09aa7ef49d58

STIX ID: report--985fa13a-35e2-5505-af7b-09aa7ef49d58

Feed Name: Centre for Cybersecurity Belgium Advisories Feed

Threat Score
90/100

Date Published: 2025-06-25

Date Updated: 2026-07-24

...
...

Critical authentication and cryptographic-signature vulnerabilities were disclosed in Quest KACE Systems Management Appliance (CVE-2025-32975, CVE-2025-32976, CVE-2025-32977, CVE-2025-32978) that can enable full administrative takeover, 2FA bypass, malicious backup uploads, and license replacement/DoS; CVE-2025-32975 (CVSS 10.0) is confirmed as actively exploited by CISA. Vendor patches are available for specific SMA versions and organizations are advised to prioritize immediate patching, increase monitoring, and report intrusions to their CERT.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.