CVE-2025-32975
Known exploited · CISA KEV
CVSS 10 CRITICAL: quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183… EPSS 2% (84th percentile).
CISA federal remediation date May 4
Vulnerabilities · 176 days ago
Arctic Wolf observed activity consistent with exploitation of CVE-2025-32975 against internet-exposed Quest KACE SMA appliances that enabled administrative takeover.
Known exploited · CISA KEV
CVSS 10 CRITICAL: quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183… EPSS 2% (84th percentile).
CISA federal remediation date May 4
2 sources covering this story
Hackers Exploit CVE-2025-32975 (CVSS 10.0) to Hijack Unpatched Quest KACE SMA Systems
CVE-2025-32975 exploited since March 2026 on unpatched KACE SMA systems, enabling admin takeover and payload delivery.
Critical Quest KACE Vulnerability Potentially Exploited in Attacks
The vulnerability is tracked as CVE-2025-32975 and it may have been exploited in attacks against the education sector.
Part of the PlainSec briefing for 2026-03-24