Hunt.io[verified]@HuntioActive Exploitation
The post announces that CVE‑2025‑32975, an auth‑bypass in Quest KACE SMA, is being actively exploited as of March 2026, offering a detailed post‑exploitation toolkit and IOCs, while noting a patch was released in May 2025.
Nicolas Krassas[verified]@DinosnActive Exploitation
The article asserts that CVE-2025-32975 is being actively exploited to hijack unpatched Quest KACE SMA systems, with no PoC, exploit code, or patch details provided.
The Cyber Security Hub™[verified]@TheCyberSecHubActive Exploitation
Hackers have actively exploited the critical CVE‑2025‑32975 to hijack unpatched Quest KACE SMA systems, as reported by The Hacker News.
piyokango[verified]@piyokangoActive Exploitation
The text announces the addition of several CVEs to CISA's known exploited vulnerability catalog, confirms that active exploitation has been observed, and provides patch references along with detailed technical information.
Hunt.io[verified]@HuntioActive Exploitation
The article confirms that CVE-2025-32975 was actively exploited in a KACE SMA breach, exposing attacker tools and a data dump that impacted many downstream organizations.
SOCRadar®[verified]@socradarActive Exploitation
CVE‑2025‑32975 is a CVSS 10.0 SSO authentication bypass in Quest KACE SMA that is actively being exploited, enabling unauthenticated attackers to achieve full administrative control. No patch or mitigation steps are mentioned.
PurpleOps[verified]@PurpleOps_ioActive Exploitation
The blog post reports that CVE-2025-32975 is currently being exploited against unpatched Quest KACE SMA devices, emphasizing the importance of real‑time threat intelligence for detection and mitigation.
Nicolas Krassas[verified]@DinosnDisclosure
The text announces a new vulnerability (CVE-2025-32975) affecting Quest KACE SMA but lacks further technical or mitigation details.