<img height="1" width="1" style="display: none" alt="" src="https://px.ads.linkedin.com/collect/?pid=1098858&amp;fmt=gif">

Hackers Exploit Critical Quest KACE Flaw to Take Over Management Systems

Arctic Wolf warns of CVE-2025-32975 exploit in Quest KACE SMA, urging immediate patches to prevent unauthorized control.
Content Team

Arctic Wolf detected attackers exploiting CVE-2025-32975, a critical authentication bypass vulnerability in Quest KACE Systems Management Appliance (SMA). The flaw, patched in May 2025, lets hackers impersonate legitimate users and gain full administrative control of unpatched systems exposed to the internet.

The attacks began around March 2026, targeting organizations including those in education. Attackers used the vulnerability for initial access before achieving complete system takeover. KACE SMA is widely used for managing endpoints, software distribution, and patching across networks.

Arctic Wolf couldn't identify the attackers or their motives but suspects opportunistic targeting of internet-exposed appliances. Organizations must immediately patch outdated Quest KACE systems.

Source: SecurityWeek

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo