Vulnerabilities & Exploits · Web App Attack

Internet-Exposed KACE Appliances Suffer Administrative Takeover

Arctic Wolf observed activity consistent with exploitation of CVE-2025-32975 against internet-exposed Quest KACE SMA appliances that enabled administrative takeover.

2 sources · Mar 23

CVE-2025-32975

NVD KEV

Known exploited · CISA KEV

CVSS 10 CRITICAL: quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183… EPSS 2% (84th percentile).

CISA federal remediation date May 4

Timeline

Sources

Part of the PlainSec briefing for 2026-03-24

Every edition of this story: Internet-Exposed KACE Appliances Suffer Administrative Takeover

More from today