CVE-2025-32975Quest KACE SMA improper authentication, CISA KEV
What broke
Quest KACE SMA failed authentication (CWE-287). CISA added it to KEV. The exact exploit path is less important than the product class: a systems-management appliance that can push software and scripts to every endpoint.
Why it matters
KACE, N-able, PaperCut, and Ivanti keep landing on KEV for the same reason. They are identity-adjacent control planes with internet-facing logins. An auth bypass there is ransomware's favorite first step.
What to do
- Patch KACE now if it is reachable. If you do not need it on the internet, take it off.
- Hunt for new admin users and unexpected script deployments around the KEV date.
- Put appliance admin behind phishing-resistant MFA and a jump host.
After you patch
Remote management and support platforms are standing administrative access to every endpoint beneath them, which turns a single bypass into a many-customer incident.
- Revoke sessions and rotate the platform's own credentials, including agent enrolment keys.
- Review remote session logs for connections you cannot attribute to a technician.
- Look for independent egress the attacker may have added, such as new tunnel services or remote access tools on managed endpoints, because removing them from the console does not remove them from the network.
- Treat the platform as tier-zero privileged access in your access model going forward, not as IT tooling.
Sources
- NVD: CVE-2025-32975
- CISA Known Exploited Vulnerabilities catalog
Related identity CVEs
Related on Start with Identity
- CVEConnectWise ScreenConnect auth bypass via an alternate path
ScreenConnect 23.9.7 and earlier skipped authentication on an alternate setup path (CWE-288). Attackers created admin users within hours. CISA KEV. CVSS 10.0. P
- CVEFortiWeb auth bypass and path traversal, admin creation
FortiWeb authentication bypass plus path traversal that lets an attacker create an admin. CVSS 9.8. Added to CISA KEV around 14 November 2025, before the Decemb
- CVEIvanti Connect Secure authentication bypass
Connect Secure and Policy Secure skipped authentication on a path that later chained with CVE-2024-21887 for unauthenticated RCE. CISA KEV. January 2024 disclos
- Blog24,650 exposed server management interfaces leak crackable password hashes before login
Firmware security firm Lava found that 67 percent of 36,872 internet-exposed Baseboard Management Controllers hand over IPMI authentication hashes before a logi
- BlogA CVE ID is a name. The value is knowing who the attacker becomes.
We opened a practitioner catalog of identity CVEs: what broke, why IAM teams should care, and what to do this week. Not an NVD mirror. A place to triage SAML wr
- RankingBest PAM Tools: Top 5 Privileged Access Management Platforms
The top 5 PAM tools (CyberArk, BeyondTrust, Delinea, Teleport, HashiCorp Boundary), scored on a 10-dimension rubric, with where each one wins and who should loo