Identity CVE · Other
CVE-2025-32975Quest KACE SMA improper authentication, CISA KEV
criticalCISA KEVActively exploited
Product: Quest KACE Systems Management ApplianceVendor: QuestCWE-287Disclosed: 2025-04-02Status: Actively exploitedNVD ↗CISA KEV ↗
What broke
Quest KACE SMA failed authentication (CWE-287). CISA added it to KEV. The exact exploit path is less important than the product class: a systems-management appliance that can push software and scripts to every endpoint.
Why it matters
KACE, N-able, PaperCut, and Ivanti keep landing on KEV for the same reason. They are identity-adjacent control planes with internet-facing logins. An auth bypass there is ransomware's favorite first step.
What to do
- Patch KACE now if it is reachable. If you do not need it on the internet, take it off.
- Hunt for new admin users and unexpected script deployments around the KEV date.
- Put appliance admin behind phishing-resistant MFA and a jump host.
Sources
- NVD: CVE-2025-32975
- CISA Known Exploited Vulnerabilities catalog
Related identity CVEs
Know a primary source we should add, or a patch status that has changed? Email [email protected]. See all briefs in the identity CVE catalog, or volunteer as a CVE Analyst.
Compiled from vendor advisories, NVD, CISA KEV, and public research. CVSS figures can disagree across NVD and the CNA. Confirm affected versions against the vendor advisory before you patch. Independent, community-driven analysis. See the disclaimer.