www.cisa.gov 4/21/2026, 12:59:05 AM · via preferred

Quest KACE SMA flaw lets attackers bypass authentication

CyberSIXT Evidence Panel Source marked as original reporting
CISA KEV Listed in KEV
Patch Patch Status Unknown

ACCORDING to CISA's Known Exploited Vulnerabilities Catalog, CVE-2025-32975 concerns the Quest KACE Systems Management Appliance (SMA) and is described as an improper authentication vulnerability that could allow attackers to impersonate legitimate users without valid credentials. The entry notes related CWE-287 and states that it is unknown whether it has been used in ransomware campaigns.

Date Added is 20 April 2026 and the Due Date is 4 May 2026, with guidance to apply vendor mitigations, follow BOD 22-01 for cloud services, or discontinue use if mitigations are unavailable. The KEV page further provides links to Quest’s response and to the NVD entry for CVE-2025-32975. This item is listed under Quest with the vulnerability affecting the KACE SMA product, and the page offers formats such as CSV and JSON for download.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline