CVE-2025-32975
Sfruttamento noto · CISA KEV
CVSS 10 CRITICAL: quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183… EPSS 2% (84º percentile).
Data di correzione federale CISA 4 mag
Vulnerabilità · 190 giorni fa
Lo sfruttamento ha permesso il dirottamento di account amministrativi e l'esecuzione di comandi remoti.
Sfruttamento noto · CISA KEV
CVSS 10 CRITICAL: quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183… EPSS 2% (84º percentile).
Data di correzione federale CISA 4 mag
2 fonti che coprono questa storia
Hackers Exploit CVE-2025-32975 (CVSS 10.0) to Hijack Unpatched Quest KACE SMA Systems
CVE-2025-32975 exploited since March 2026 on unpatched KACE SMA systems, enabling admin takeover and payload delivery.
Critical Quest KACE Vulnerability Potentially Exploited in Attacks
The vulnerability is tracked as CVE-2025-32975 and it may have been exploited in attacks against the education sector.
Part of the PlainSec briefing for 2026-03-24