CVE-2025-32975
Sfruttamento noto · CISA KEV
CVSS 10 CRITICAL: quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183… EPSS 2% (84º percentile).
Data di correzione federale CISA 4 mag
Vulnerabilità ed exploit · Attacco ad app web
Lo sfruttamento ha permesso il dirottamento di account amministrativi e l'esecuzione di comandi remoti.
2 fonti · 23 mar
Sfruttamento noto · CISA KEV
CVSS 10 CRITICAL: quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183… EPSS 2% (84º percentile).
Data di correzione federale CISA 4 mag
The Hacker News
Hackers Exploit CVE-2025-32975 (CVSS 10.0) to Hijack Unpatched Quest KACE SMA Systems
CVE-2025-32975 exploited since March 2026 on unpatched KACE SMA systems, enabling admin takeover and payload delivery.
originaleSecurityWeek
Critical Quest KACE Vulnerability Potentially Exploited in Attacks
The vulnerability is tracked as CVE-2025-32975 and it may have been exploited in attacks against the education sector.
originalePart of the PlainSec briefing for 2026-03-24
Every edition of this story: Appliance KACE Esposte Subiscono Dirottamento Amministrativo