CVE-2025-32975
Known exploited · CISA KEV
CVSS 10 CRITICAL: quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183… EPSS 2% (84th percentile).
CISA federal remediation date May 4
Vulnerabilities & Exploits · Web App Attack
Arctic Wolf observed activity consistent with exploitation of CVE-2025-32975 against internet-exposed Quest KACE SMA appliances that enabled administrative takeover.
2 sources · Mar 23
Known exploited · CISA KEV
CVSS 10 CRITICAL: quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183… EPSS 2% (84th percentile).
CISA federal remediation date May 4
The Hacker News
Hackers Exploit CVE-2025-32975 (CVSS 10.0) to Hijack Unpatched Quest KACE SMA Systems
CVE-2025-32975 exploited since March 2026 on unpatched KACE SMA systems, enabling admin takeover and payload delivery.
originalSecurityWeek
Critical Quest KACE Vulnerability Potentially Exploited in Attacks
The vulnerability is tracked as CVE-2025-32975 and it may have been exploited in attacks against the education sector.
originalPart of the PlainSec briefing for 2026-03-24
Every edition of this story: Internet-Exposed KACE Appliances Suffer Administrative Takeover