logo

CVE-2025-32975

ID: 9663ec74-51ee-52fa-95d8-bec066b5d00f

STIX ID: report--9663ec74-51ee-52fa-95d8-bec066b5d00f

Feed Name: Arctic Wolf Blog

Threat Score
80/100

Date Published: 2026-03-19

Date Updated: 2026-06-11

...
...

Arctic Wolf observed active exploitation of a critical authentication-bypass (CVE-2025-32975) in publicly exposed, unpatched Quest KACE SMA appliances that resulted in administrative takeover, credential harvesting (Mimikatz), and lateral movement to backup infrastructure and domain controllers; the report includes technical indicators (e.g., download IP 216.126.225.156), recommended fixed versions, and guidance to remove internet-facing instances.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.