LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-32975: Quest KACE Systems Management Appliance (SMA) Improper Authentication Vulnerability

RBRecent Breaches Vulnerability Intelligence·Apr 20, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 4, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-32975 to its Known Exploited Vulnerabilities catalog on Apr 20, 2026, with a federal patch deadline of May 4, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Quest KACE Systems Management Appliance (SMA) contains an improper authentication vulnerability that could allow attackers to impersonate legitimate users without valid credentials.

Quest KACE Systems Management Appliance (SMA) contains an improper authentication vulnerability identified as CVE-2025-32975. The flaw could allow attackers to impersonate legitimate users without valid credentials. This matters for organizations that rely on the appliance to manage endpoints, because successful impersonation could grant unauthorized control over managed systems and the data they hold.

How it works

CWE-287 covers improper authentication, a class of weakness in which an application does not correctly verify the identity of a user or process before granting access to protected functions or data.

An attacker could abuse this weakness by supplying requests that the affected component accepts without performing the expected credential validation. The precise request format and any conditions required for success are not described in the available summary and must be confirmed against the vendor advisory.

Am I affected? How to find it in your systems

Quest KACE Systems Management Appliance (SMA) is typically deployed as an on-premises server that centralizes inventory, patching, and configuration tasks for Windows, macOS, and Linux endpoints.

How to remediate

Apply the vendor-supplied update or configuration change referenced in the official advisory as the primary remediation step.

If you can't patch immediately

Until the vendor instructions can be followed, reduce exposure by placing the appliance behind network segmentation that limits inbound connections to only the management workstations that require access.

If your data may have been exposed

Improper-authentication vulnerabilities that are actively exploited can lead to unauthorized access and subsequent data exposure. Organizations can run a free exposure scan of their email addresses against known breach data to determine whether any accounts have already appeared in public data sets.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedQuest · KACE Systems Management Appliance (SMA)
WeaknessCWE-287
Added to CISA KEVApr 20, 2026
Federal patch deadlineMay 4, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities