Vulnerabilities & Exploits · Web App Attack

Internet-Exposed KACE Appliances Suffer Administrative Takeover

The authentication-bypass flaw enabled administrative takeover of affected appliances. Some affected customers were in the education sector.

2 sources · Mar 23

CVE-2025-32975

NVD KEV

Known exploited · CISA KEV

CVSS 10 CRITICAL: quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183… EPSS 2% (84th percentile).

CISA federal remediation date May 4

Timeline

Sources

Part of the PlainSec briefing for 2026-03-22

Every edition of this story: Internet-Exposed KACE Appliances Suffer Administrative Takeover

More from today