Hackers Exploit CVE-2025-32975 (CVSS 10.0) to Hijack Unpatched Quest KACE SMA Systems

Arctic Wolf reports that a maximum-severity security vulnerability affecting Quest KACE Systems Management Appliance (SMA) may be being exploited by threat actors.

The cybersecurity firm claimed to have seen malicious activity in client environments beginning the week of March 9, 2026, which is consistent with the exploitation of CVE-2025-32975 on unpatched SMA systems that are online. The attack’s ultimate objectives are yet unknown.

An authentication bypass vulnerability known as CVE-2025-32975 (CVSS score: 10.0) enables attackers to pretend to be authentic users without having the right credentials. If the vulnerability is successfully exploited, administrative accounts could be fully taken over. Quest fixed the problem in May 2025.

Threat actors are thought to have exploited the vulnerability in the malicious activity found by Arctic Wolf in order to take over administrative accounts and carry out remote instructions read more about Hackers Exploit CVE-2025-32975 (CVSS 10.0) to Hijack Unpatched Quest KACE SMA Systems.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *