CVE-2025-32975Active Exploitation(quest / kace_systems_management_appliance)

CRITICALCVSS 10.0 · CRITICALCISA KEV

Exploitation observed; activity peaked at 53 mentions and remains active

Immediate actions

  • Patch quest kace_systems_management_appliance systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (Patch 4) contains an authentication bypass vulnerability that allows attackers to impersonate legitimate users without valid credentials. The vulnerability exists in the SSO authentication handling mechanism and can lead to complete administrative takeover.

8.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-05-04. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-287

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • kace_systems_management_appliance

Threat summary

  • Active exploitation appears in 97 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 122 mentions across 23 observed days

What's happening

  • Active exploitation reported across 97 signals
  • Exploit tool or code specified in 4 signals
  • PoC mentioned or linked in 11 signals
  • Patch or workaround mentioned in 31 signals
  • Technical details provided in 80 signals
  • Disclosure: 10 classified signals
  • General: 9 classified signals
  • Peaked 18d ago at 53 mentions (2026-03-23); latest day: 1
  • 122 total mentions across 23 days

Affected systems

Vendors
Products
kace_systems_management_appliance

Deep dive

Activity timeline122 mentions / 23d
013274053Mentions · 2026-03-19: 1Mentions · 2026-03-20: 3Mentions · 2026-03-21: 6Mentions · 2026-03-22: 1Mentions · 2026-03-23: 53Mentions · 2026-03-24: 18Mentions · 2026-03-25: 5Mentions · 2026-03-27: 1Mentions · 2026-03-30: 3Mentions · 2026-04-03: 1Mentions · 2026-04-04: 1Mentions · 2026-04-20: 4Mentions · 2026-04-21: 5Mentions · 2026-04-22: 4Mentions · 2026-04-26: 1Mentions · 2026-04-27: 1Mentions · 2026-05-12: 2Mentions · 2026-05-13: 5Mentions · 2026-05-14: 3Mentions · 2026-05-15: 1Mentions · 2026-05-16: 1Mentions · 2026-05-18: 1Mentions · 2026-06-05: 1PoC Mentioned / Linked · 2026-03-23: 9PoC Mentioned / Linked · 2026-03-24: 2Exploit Tool / Code · 2026-03-23: 2Exploit Tool / Code · 2026-03-24: 2Active Exploitation · 2026-03-19: 1Active Exploitation · 2026-03-20: 3Active Exploitation · 2026-03-21: 5Active Exploitation · 2026-03-22: 1Active Exploitation · 2026-03-23: 50Active Exploitation · 2026-03-24: 14Active Exploitation · 2026-03-25: 5Active Exploitation · 2026-03-27: 1Active Exploitation · 2026-03-30: 3Active Exploitation · 2026-04-20: 1Active Exploitation · 2026-04-21: 3Active Exploitation · 2026-04-22: 2Active Exploitation · 2026-04-26: 1Active Exploitation · 2026-05-12: 2Active Exploitation · 2026-05-14: 1Active Exploitation · 2026-05-15: 1Active Exploitation · 2026-05-16: 1Active Exploitation · 2026-05-18: 1Active Exploitation · 2026-06-05: 1Patch / Workaround · 2026-03-20: 2Patch / Workaround · 2026-03-21: 3Patch / Workaround · 2026-03-23: 8Patch / Workaround · 2026-03-24: 6Patch / Workaround · 2026-03-30: 2Patch / Workaround · 2026-04-20: 2Patch / Workaround · 2026-04-21: 1Patch / Workaround · 2026-04-22: 4Patch / Workaround · 2026-04-26: 1Patch / Workaround · 2026-05-12: 1Patch / Workaround · 2026-05-16: 1Technical Details · 2026-03-20: 2Technical Details · 2026-03-21: 1Technical Details · 2026-03-22: 1Technical Details · 2026-03-23: 44Technical Details · 2026-03-24: 10Technical Details · 2026-03-25: 3Technical Details · 2026-03-27: 1Technical Details · 2026-03-30: 2Technical Details · 2026-04-20: 3Technical Details · 2026-04-21: 5Technical Details · 2026-04-22: 3Technical Details · 2026-04-26: 1Technical Details · 2026-04-27: 1Technical Details · 2026-05-12: 1Technical Details · 2026-05-15: 1Technical Details · 2026-05-16: 103-1903-2103-2303-2503-3004-0404-2104-2605-1205-1405-1606-05
Signal classification5 categories
Active Exploitation
9678.7%
Disclosure
108.2%
General
97.4%
Patch
64.9%
Exploit
10.8%
Referenced assets89 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-191
Active Exploitation1
2026-03-203
Active Exploitation3
2026-03-216
Active Exploitation6
2026-03-221
Active Exploitation1
2026-03-2353
Active Exploitation49Exploit1General2Patch1
2026-03-2418
Active Exploitation14Disclosure1General3
2026-03-255
Active Exploitation5
2026-03-271
Active Exploitation1
2026-03-303
Active Exploitation3
2026-04-031
Disclosure1
2026-04-041
Disclosure1
2026-04-204
Active Exploitation1General1Patch2
2026-04-215
Active Exploitation3Disclosure1General1
2026-04-224
Active Exploitation1Patch3
2026-04-261
Active Exploitation1
2026-04-271
Disclosure1
2026-05-122
Active Exploitation2
2026-05-135
Disclosure3General2
2026-05-143
Active Exploitation1Disclosure2
2026-05-151
Active Exploitation1
2026-05-161
Active Exploitation1
2026-05-181
Active Exploitation1
2026-06-051
Active Exploitation1
Full discourse20 posts
  • Gray Hats@the_yellow_fall
    Active Exploitation

    Arctic Wolf warns that hackers are actively exploiting a critical Quest KACE vulnerability (CVE-2025-32975) to completely take over enterprise networks. #QuestKACE #CVE #CyberSecurity #InfoSec #NetworkSecurity #Vulnerability #ArcticWolf #PatchAlert https://securityonline.info/critical-quest-kace-flaw-exploited-network-takeover-cve-2025-32975/ https://t.co/REKy60eb6J

    Post summary

    Arctic Wolf reports that hackers are actively exploiting CVE‑2025‑32975 to take full control of enterprise networks.

    141114589
    10.7K followersView on X
  • Gray Hats@the_yellow_fall
    Active Exploitation

    Quest KACE SMA CVE-2025-32975 (CVSS 10) exploited in the wild. Attackers bypass auth to seize admin control. Patch to version 14.1.101 or 14.0.341 now! #QuestKACE #CyberSecurity #InfoSec #EndpointManagement #VulnerabilityAlert #CVE #SupplyChainAttack https://securityonline.info/quest-kace-sma-vulnerability-cve-2025-32975-exploited-cvss-10/ https://t.co/lSXALOSpdp

    Post summary

    CVE‑2025‑32975 is actively exploited in the wild, allowing attackers to bypass authentication and gain administrative control; a patch is available for affected versions.

    020952.9K
    12.5K followersView on X
  • Hunt.io@Huntio
    Active Exploitation

    🚨 NEW RESEARCH: CVE-2025-32975 - How the Quest KACE SMA Breach Exposed 60+ Organizations CVE-2025-32975 is a CVSS 10.0 auth bypass in Quest KACE SMA. Patch dropped May 2025. Active exploitation tracked as recently as March 2026: https://hunt.io/blog/cve-2025-32975-quest-kace-sma-open-directory-60-victims http://Hunt.io AttackCapture captured the attacker's open C2 directory on March 12. 219 files, 308 MB, no auth required. What was inside: - Primary victim: HIQ, a Boston-area MSP - 60+ named client orgs downstream across law enforcement, government, healthcare, and education - Full post-exploitation toolkit: reverse shell, SOCKS5 tunnel, SMB credential sprayer, WMI domain recon 512 MB MariaDB dump from the production KACE appliance, including managed device records and 10 internal operator accounts - Hardcoded credentials from at least 2 additional victim environments - LNK metadata pointing to a Windows Server 2019 VPS as the operator's machine Over 12,000 K1000 instances are still internet-facing and unpatched. 👉 Full toolkit breakdown and , IOCs: https://hunt.io/blog/cve-2025-32975-quest-kace-sma-open-directory-60-victims

    Post summary

    The post announces that CVE‑2025‑32975, an auth‑bypass in Quest KACE SMA, is being actively exploited as of March 2026, offering a detailed post‑exploitation toolkit and IOCs, while noting a patch was released in May 2025.

    040641.8K
    6.7K followersView on X
  • Pierluigi Paganini - Security Affairs@securityaffairs
    General

    #Quest #KACE #SMA flaw CVE-2025-32975: when one unpatched tool opens the door to 60 organizations https://securityaffairs.com/192067/hacking/quest-kace-sma-flaw-cve-2025-32975-when-one-unpatched-tool-opens-the-door-to-60-organizations.html #securityaffairs #hacking @Huntio

    Post summary

    The post refers to CVE‑2025‑32975 and highlights a potential risk to multiple organizations, but it provides no concrete proof of concept, exploit code, active exploitation evidence, patch information, or technical details.

    040441.9K
    37.6K followersView on X
  • Arctic Wolf@AWNetworks
    Active Exploitation

    Arctic Wolf has observed malicious activity in customer environments potentially linked to the exploitation of CVE-2025-32975 on unpatched Quest KACE Systems Management Appliance (SMA) instances that were publicly exposed to the internet: https://arcticwolf.com/resources/blog/cve-2025-32975/?utm_source=twitter&utm_medium=social&utm_campaign=ADV%20FY26%20Social%20Twitter

    Post summary

    Arctic Wolf reports that malicious activity linked to CVE-2025-32975 was observed against unpatched Quest KACE SMA instances exposed to the internet.

    03081918
    4.5K followersView on X
  • Nicolas Krassas@Dinosn
    Active Exploitation

    Hackers Exploit CVE-2025-32975 (CVSS 10.0) to Hijack Unpatched Quest KACE SMA Systems https://thehackernews.com/2026/03/hackers-exploit-cve-2025-32975-cvss-100.html

    Post summary

    The article asserts that CVE-2025-32975 is being actively exploited to hijack unpatched Quest KACE SMA systems, with no PoC, exploit code, or patch details provided.

    011721.7K
    153.5K followersView on X
  • The Cyber Security Hub™@TheCyberSecHub
    Active Exploitation

    Hackers Exploit CVE-2025-32975 (CVSS 10.0) to Hijack Unpatched Quest KACE SMA Systems https://thehackernews.com/2026/03/hackers-exploit-cve-2025-32975-cvss-100.html?utm_source=dlvr.it&utm_medium=twitter

    Post summary

    Hackers have actively exploited the critical CVE‑2025‑32975 to hijack unpatched Quest KACE SMA systems, as reported by The Hacker News.

    13150711
    193.8K followersView on X
  • Autumn Good@autumn_good_35
    Active Exploitation

    このアクターによる攻撃では同様のツールがまた使われるでしょうからハンティング等に活用できそうですね。 CVE-2025-32975: The Open Directory Behind the KACE SMA Breach and 60+ Downstream Victims https://hunt.io/blog/cve-2025-32975-quest-kace-sma-open-directory-60-victims

    Post summary

    The text references CVE-2025-32975 as having been actively abused, resulting in over 60 downstream victims, but it does not provide PoC details, exploit code, patches, or technical specifics.

    010442.2K
    6.9K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(4/20追加) 🛡️No.1571 CVE-2026-20122 Cisco Catalyst SD-WAN Manager Incorrect Use of Privileged APIs Vulnerability ✅概要 ・深刻度:重要 7.1 (CVSS Base) / Cisco Systems, Inc. (CNA) ・種別:特権 API の不適切な使用 (CWE-648) ・CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Cisco Catalyst SD-WAN Manager の API において、認証されたリモートの攻撃者がローカルファイルシステム上の任意のファイルを上書きできる脆弱性。悪用には影響を受けるシステムに対する API アクセス権を持つ有効な読み取り専用資格情報が必要。事前認証されていない攻撃者により、任意ファイルの上書きに加え、vmanage ユーザー権限を取得される恐れがある。 ________________________________________ ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:中 ________________________________________ ✅攻撃前提条件 ・Cisco Catalyst SD-WAN Manager の脆弱バージョンが稼働していること。 ・攻撃者が対象システムへネットワーク越しに到達可能であること。 ・攻撃者が API アクセス権を持つ有効な読み取り専用資格情報を有していること。 ________________________________________ ✅悪用時影響 ・ローカルファイルシステム上の任意のファイルを上書き ・vmanage ユーザー権限を取得 ________________________________________ ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:確認済み。Cisco PSIRT は、2026年3月に、CVE-2026-20128 および CVE-2026-20122 の悪用を把握したと報告。 ________________________________________ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2026-20122 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-authbp-qwCX8D4v https://www.cisa.gov/news-events/directives/ed-26-03-mitigate-vulnerabilities-cisco-sd-wan-systems https://www.cisa.gov/news-events/directives/supplemental-direction-ed-26-03-hunt-and-hardening-guidance-cisco-sd-wan-systems 🛡️No.1572 CVE-2026-20133 Cisco Catalyst SD-WAN Manager Exposure of Sensitive Information to an Unauthorized Actor Vulnerability ✅概要 ・深刻度:重要 7.5 (CVSS Base) / NVD ・種別:情報漏えい (CWE-200) ・CVSS: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Cisco Catalyst SD-WAN Manager において、事前認証されていない攻撃者により、機密情報を摂取される恐れがある。原因はファイルシステムのアクセス制限が不十分なためで、攻撃者は対象システムのAPIにアクセスして悪用。 ________________________________________ ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:低 ________________________________________ ✅攻撃前提条件 ・Cisco Catalyst SD-WAN Manager の脆弱バージョンが稼働していること。 ・攻撃者が対象システムへネットワーク越しに到達可能であること。 ・認証は不要。 ________________________________________ ✅悪用時影響 ・該当システム上の機密情報を閲覧 ・基盤となるオペレーティングシステム上の機密情報を読み取られる ________________________________________ ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:公開情報確認できず ________________________________________ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2026-20133 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-authbp-qwCX8D4v 🛡️No.1573 CVE-2025-2749 Kentico Xperience Path Traversal Vulnerability ✅概要 ・深刻度:重要 7.2 (CVSS Base) / VulnCheck (CNA) ・種別:パス・トラバーサル、 危険なタイプのファイルの無制限アップロード(CWE-22,CWE-434) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H (NVD) Kentico Xperience 13.0.178以前に、認証済の攻撃者によって、Staging Sync Server経由で任意の相対パスへデータをアップロード可能な脆弱性が存在。パストラバーサルと任意ファイルアップロードを経てサーバサイドで実行可能なコンテンツ配置によるリモートコード実行を行われる恐れがある。 ________________________________________ ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:中 ________________________________________ ✅攻撃前提条件 ・Kentico Xperience 13.0.177以前が稼働していること。 ・Staging Serviceが有効であること。 ・Staging Serviceがユーザー名/パスワード認証で構成されていること。 ・攻撃者がStaging Sync Serverに対する有効な認証済み権限を有すること。 ________________________________________ ✅悪用時影響 ・任意ファイルアップロードにより、サーバサイドで実行可能なコンテンツを配置 ・リモートコードの実行 ________________________________________ ✅悪用事例等に関する公開情報 ・PoC/Exploit:一部公開(技術情報のみ) ・ITW:未確認 ________________________________________ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2025-2749 https://devnet.kentico.com/download/hotfixes 🛡️No.1574 CVE-2023-27351 PaperCut NG/MF Improper Authentication Vulnerability ✅概要 ・深刻度:重要 8.2 (CVSS Base) / NVD ・種別:不適切な認証 (CWE-287) ・CVSS: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N PaperCut NG/MFのApplication Serverにおいて、事前認証されていない攻撃者により、リモートからユーザー情報を取得される恐れがある。対象となる情報に、PaperCutは、ユーザー名、氏名、メールアドレス、部署情報、カード番号に加え、内部作成ユーザーのハッシュ化パスワードを取得され得ると報告。 ________________________________________ ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:低 ________________________________________ ✅攻撃前提条件 ・PaperCut NG/MFのApplication Serverが脆弱バージョンで稼働していること。 ・攻撃者が対象サーバへネットワーク越しに到達可能であること。 ・認証は不要。 ________________________________________ ✅悪用時影響 ・認証を回避して、ユーザー名、氏名、メールアドレス、部署情報、カード番号などのユーザー情報を取得 ・内部作成ユーザーに限り、ハッシュ化されたパスワードを取得 ________________________________________ ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず (GitHub) ・ITW:未確認 (PaperCut) ________________________________________ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2023-27351 https://www.papercut.com/kb/Main/PO-1216-and-PO-1219 🛡️No.1575 CVE-2025-48700 Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability ✅概要 ・深刻度:注意6.1 (CVSS Base) / CISA-ADP ・種別:クロスサイトスクリプティング (CWE-79) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Zimbra Collaboration (ZCS) 8.8.15、9.0、10.0、10.1 の Classic UI において、HTMLコンテンツの不十分なサニタイズにより、ユーザーのセッション内で任意のJavaScriptを実行される恐れがある。細工されたタグ構造や属性値に含まれる @ import ディレクティブなどのスクリプト注入ベクトルが原因。 ________________________________________ ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:中 ________________________________________ ✅攻撃前提条件 ・Zimbra Collaboration (ZCS) 8.8.15、9.0、10.0、10.1 の脆弱バージョンが稼働していること。 ・攻撃者が細工した電子メールメッセージを対象ユーザーに閲覧させること。 ・Classic UI で細工された電子メールメッセージが閲覧されること。 ・追加の利用者操作は不要。 ________________________________________ ✅悪用時影響 ・ユーザーのセッション内で任意のJavaScriptを実行 ・機微情報への不正アクセスにつながる ________________________________________ ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:未確認 ________________________________________ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2025-48700 https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories 🛡️No.1576 CVE-2026-20128 Cisco Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format Vulnerability ✅概要 ・深刻度:重要 7.5 (CVSS Base) / Cisco Systems, Inc. (CNA) ・種別:復元可能な形式でのパスワード保存 (CWE-257) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Cisco Catalyst SD-WAN Manager の Data Collection Agent(DCA)機能において、事前認証されていない攻撃者により、リモートから DCA ユーザー権限を取得される恐れがある。影響を受けるシステム上に DCA ユーザーの認証情報ファイルが存在することで、細工された HTTP 要求により当該ファイルを読み取られる可能性。 ________________________________________ ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:低 ________________________________________ ✅攻撃前提条件 ・Cisco Catalyst SD-WAN Manager の脆弱バージョンが稼働していること。 ・攻撃者が対象システムへネットワーク越しに到達可能であること。 ・認証は不要。 ________________________________________ ✅悪用時影響 ・DCA パスワードを含むファイルを読み取られる ・別の影響を受けるシステムへアクセスされ、DCA ユーザー権限を取得される ・機密情報へアクセスされる ________________________________________ ✅悪用事例等に関する公開情報 ・PoC/Exploit:一部公開(技術情報のみ) ・ITW:確認済み。Cisco PSIRT は、2026年3月に、CVE-2026-20128 および CVE-2026-20122 の悪用を把握したと報告。 ________________________________________ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2026-20128 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-authbp-qwCX8D4v   🛡️No.1577 CVE-2025-32975 Quest KACE Systems Management Appliance (SMA) Improper Authentication Vulnerability ✅概要 ・深刻度:緊急 10.0 (CVSS Base) / CISA-ADP ・種別:不適切な認証 (CWE-287) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H Quest KACE Systems Management Appliance (SMA) には、事前認証されていない攻撃者により、正規ユーザーになりすませる認証回避の脆弱性が存在。SSO認証処理に起因し他脆弱性で、完全な管理者乗っ取りをされる恐れがある。 ________________________________________ ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:低 ________________________________________ ✅攻撃前提条件 ・Quest KACE Systems Management Appliance (SMA) の脆弱バージョンが稼働していること。 ・対象機器がネットワーク越しに到達可能であること。 ・認証は不要。 ________________________________________ ✅悪用時影響 ・正当な認証情報なしに正規ユーザーになりすまされる ・完全な管理者権限を取得される ・アプライアンスを全面的に掌握される ________________________________________ ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:確認済み。Arctic Wolf は、2026年3月9日の週から、インターネット公開された未パッチのKACE SMAに対するCVE-2025-32975悪用の可能性がある不正活動を顧客環境で観測したと報告。 ________________________________________ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2025-32975 https://support.quest.com/kb/4379499/quest-response-to-kace-sma-vulnerabilities-cve-2025-32975-cve-2025-32976-cve-2025-32977-cve-2025-32978 🛡️No.1578 CVE-2024-27199 JetBrains TeamCity Relative Path Traversal Vulnerability ✅概要 ・深刻度:重要 7.3 (CVSS Base) / JetBrains s.r.o. (CNA) (NVD) ・種別:相対パストラバーサル (CWE-23) (NVD) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L (NVD) JetBrains TeamCity 2023.11.4未満に相対パストラバーサルの脆弱性が存在。事前認証されていない攻撃者により、HTTP(S)経由で認証チェックを回避し、TeamCityサーバの管理権限を取得される恐れがある。 ________________________________________ ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:低 ________________________________________ ✅攻撃前提条件 ・TeamCity On-Premises 2023.11.3以前が稼働していること。 ・攻撃者が対象のTeamCityサーバへHTTP(S)アクセス可能であること。 ・認証は不要。 ________________________________________ ✅悪用時影響 ・認証チェックを回避され、限定的な管理者アクションを実行される ・TeamCityサーバの管理権限を取得される ・機密情報の取得、設定情報の改変、サービス影響につながる ________________________________________ ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開済み (NVD) ・ITW:確認済み。トレンドマイクロは、CVE-2024-27198およびCVE-2024-27199を悪用しようとする攻撃者活動を確認したと報告。 ________________________________________ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2024-27199 https://blog.jetbrains.com/teamcity/2024/03/additional-critical-security-issues-affecting-teamcity-on-premises-cve-2024-27198-and-cve-2024-27199-update-to-2023-11-4-now/ https://www.cisa.gov/news-events/alerts/2026/04/20/cisa-adds-eight-known-exploited-vulnerabilities-catalog #vulnerability

    Post summary

    The text announces the addition of several CVEs to CISA's known exploited vulnerability catalog, confirms that active exploitation has been observed, and provides patch references along with detailed technical information.

    000415.9K
    43.6K followersView on X
  • Hunt.io@Huntio
    Active Exploitation

    📌 Another Look at the Open Directory Behind the KACE SMA Breach A few weeks ago, we published an investigation into the KACE SMA breach tied to CVE-2025-32975. The open directory we captured exposed the attacker’s toolkit: reverse shells, SMB spraying, WMI recon, tunneling tools, Tor Browser, and a MariaDB dump from a production KACE appliance. That dump pointed to HIQ, an MSP whose KACE instance managed endpoints for 60+ downstream organizations. One exposed management platform can put a lot of downstream organizations at risk. Read the full article in our blog 👉 https://hunt.io/blog/cve-2025-32975-quest-kace-sma-open-directory-60-victims #ThreatHunting #ThreatIntelligence #CyberSecurity

    Post summary

    The article confirms that CVE-2025-32975 was actively exploited in a KACE SMA breach, exposing attacker tools and a data dump that impacted many downstream organizations.

    01021506
    6.7K followersView on X
  • SOCRadar®@socradar
    Active Exploitation

    A CVSS 10.0 vulnerability (CVE-2025-32975) in Quest KACE SMA is under active exploitation. This SSO authentication bypass allows unauthenticated attackers to achieve full administrative takeover on exposed systems. Read more at the link below. https://hubs.la/Q047V_Rg0 #CyberSecurity #Vulnerability #ThreatIntel

    Post summary

    CVE‑2025‑32975 is a CVSS 10.0 SSO authentication bypass in Quest KACE SMA that is actively being exploited, enabling unauthenticated attackers to achieve full administrative control. No patch or mitigation steps are mentioned.

    10021292
    5.6K followersView on X
  • moton@moton
    Active Exploitation

    CVE-2025-32975: Arctic Wolf Observes Exploitation of Quest KACE Systems Management Appliance - https://arcticwolf.com/resources/blog/cve-2025-32975/

    Post summary

    Arctic Wolf reports observing real‑world exploitation of Quest KACE Systems Management Appliance via CVE‑2025‑32975, though the snippet lacks PoC, exploit code, or detailed technical data.

    01030235
    658 followersView on X
  • Securízame@Securizame
    Active Exploitation

    Explotación activa de CVE-2025-32975 permite tomar el control de Quest KACE SMA sin parchear https://unaaldia.hispasec.com/2026/03/explotacion-activa-de-cve-2025-32975-permite-tomar-el-control-de-quest-kace-sma-sin-parchear.html #Internet #Noticia #Tecnología #ciberSeguridad vía @unaaldia https://t.co/fbYAmrG2AE

    Post summary

    Reported active exploitation of CVE‑2025‑32975 in Quest KACE SMA enabling remote takeover without a patch, as detailed in a security news article.

    00021286
    15.3K followersView on X
  • PurpleOps@PurpleOps_io
    Active Exploitation

    📝 𝐍𝐞𝐰 𝐨𝐧 𝐭𝐡𝐞 𝐛𝐥𝐨𝐠: Unpatched Quest KACE SMA devices are under active attack leveraging CVE-2025-32975. Learn how real-time threat intelligence helps detect and mitigate these attacks. Read it here → https://www.purple-ops.io/cybersecurity-threat-intelligence-blog/real-time-ransomware-intelligence-kace/ Join the conversation and share your view!

    Post summary

    The blog post reports that CVE-2025-32975 is currently being exploited against unpatched Quest KACE SMA devices, emphasizing the importance of real‑time threat intelligence for detection and mitigation.

    2001053
    96 followersView on X
  • Autumn Good@autumn_good_35
    Active Exploitation

    3/9週から悪用を確認しているとのこと。 CVE-2025-32975: Arctic Wolf Observes Exploitation of Quest KACE Systems Management Appliance https://arcticwolf.com/resources/blog/cve-2025-32975/

    Post summary

    Arctic Wolf reports that CVE-2025-32975 against Quest KACE Systems Management Appliance has been actively exploited in the wild since March 9, with no PoC, exploit code, patch, or detailed technical information disclosed.

    01020499
    6.7K followersView on X
  • Nicolas Krassas@Dinosn
    Disclosure

    Quest KACE SMA flaw CVE-2025-32975: when one unpatched tool opens the door to 60 organizations https://securityaffairs.com/192067/security/quest-kace-sma-flaw-cve-2025-32975-when-one-unpatched-tool-opens-the-door-to-60-organizations.html

    Post summary

    The text announces a new vulnerability (CVE-2025-32975) affecting Quest KACE SMA but lacks further technical or mitigation details.

    010102.1K
    158.6K followersView on X
  • iototsecnews@iototsecnews
    Active Exploitation

    Quest KACE SMA を標的とする攻撃チェーン:認証バイパスの脆弱性 CVE-2025-32975 を悪用 https://iototsecnews.jp/2026/03/23/hackers-exploit-quest-kace-sma-flaw-to-harvest-credentials/ この攻撃の原因は、Quest KACE SMA の SSO 認証処理メカニズムに存在する、脆弱性 CVE-2025-32975 の悪用にあります。この欠陥により、本来であれば厳重に守られるべき認証プロセスがバイパスされ、正規のユーザーになりすました攻撃者が、管理権限を握ることが可能になっています。2025年5月の時点で、すでにパッチが公開されていますが、更新が遅れている環境が狙われています。認証というシステムの入り口に不備があると、その後の多層的な防御も突破されやすくなるため、この種の脆弱性には注意が必要です。ご利用のチームは、ご注意ください。 #CVE202532975 #Exploit #KACESystemsManagementAppliance #Quest #Vulnerability

    Post summary

    Hackers are exploiting a SSO authentication bypass (CVE‑2025‑32975) in Quest KACE SMA to elevate privileges and harvest credentials, while a patch was released but many systems remain unpatched.

    01010302
    481 followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-21992 2 - CVE-2025-5777 3 - CVE-2026-3909 4 - CVE-2025-32975 5 - CVE-2008-0166 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The tweet simply enumerates trending CVE identifiers without providing additional context or actionable details about exploitation, patches, or technical characteristics.

    00020261
    1.7K followersView on X
  • 𝗛𝘂𝗺𝗮𝗻 𝗙𝗶𝗿𝗲𝘄𝗮𝗹𝗹@secguro
    Active Exploitation

    Security Patches & Updates Hackers Exploit CVE-2025-32975 (CVSS 10.0) to Hijack Unpatched Quest KACE SMA Systems

    Post summary

    Hackers are reportedly exploiting CVE-2025-32975 with CVSS 10.0 to hijack unpatched Quest KACE SMA systems, though no specific exploit code or patch information is provided.

    10010251
    19.3K followersView on X
  • kokumօtօ@__kokumoto
    Active Exploitation

    エンドポイント管理製品Quest KACE Systems Management Appliance (SMA)のCVSSスコア10の脆弱性が悪用されている。Arctic Wolf社報告。CVE-2025-32975は認証回避の脆弱性で、2025年5月に修正されたもの。 https://thehackernews.com/2026/03/hackers-exploit-cve-2025-32975-cvss-100.html

    Post summary

    CVE-2025-32975, an authentication bypass with CVSS 10 in Quest KACE SMA, is reported to be actively exploited; a patch was issued in May 2025.

    00020929
    7.3K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appquestkace_systems_management_appliance---

Explore more