Quest KACE SMA Critical Authentication Bypass Actively Exploited in Education Sector (CVE-2025-32975)

Quest KACE SMA Critical Authentication Bypass Actively (TL-2026-0267) is a critical-severity software vulnerability scored CVSS 10, first published 2026-03-21. It has no confirmed attribution, affects Quest Software KACE Systems Management Appliance (SMA), references 4 CVEs (CVE-2025-32975, CVE-2025-32976, CVE-2025-32977), maps to 18 MITRE ATT&CK techniques (T1003, T1021, T1027), and is covered by 9 detection rules and 12 indicators of compromise.

Key facts for TL-2026-0267

Threat ID
TL-2026-0267
Severity
CRITICAL
CVSS
10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
2026-03-21
Last reviewed
2026-03-21
Attribution confidence
NONE
Motivation
UNKNOWN
Target sectors
education, healthcare, government, enterprise
Target regions
North America, Europe
Detection rules
9
Indicators of compromise
12

Malware and tooling in Quest KACE SMA Critical Authentication Bypass Actively

Malware and tooling: Mimikatz

CVE-2025-32975 is a CVSS 10.0 authentication bypass in Quest KACE Systems Management Appliance (SMA) SSO handling that allows unauthenticated attackers to impersonate any user and gain full administrative control. Arctic Wolf observed active exploitation starting March 9, 2026 against education sector organizations, with attackers leveraging KPluginRunProcess for remote code execution, deploying Mimikatz for credential harvesting, and establishing C2 communications.

How Quest KACE SMA Critical Authentication Bypass Actively works

Quest KACE Systems Management Appliance (SMA) contains a critical authentication bypass vulnerability (CVE-2025-32975) in its Single Sign-On (SSO) authentication handling mechanism. The flaw allows unauthenticated remote attackers to impersonate any legitimate user — including administrators — without providing valid credentials. Successful exploitation grants complete administrative control over the KACE SMA appliance.

KACE SMA is an on-premises endpoint management platform widely deployed in education, healthcare, and government sectors for centralized asset inventory, software deployment, patching, and endpoint monitoring. Compromise of a KACE SMA instance is particularly impactful because the appliance manages and has privileged access to all enrolled endpoints across the organization, enabling rapid lateral movement and full network takeover.

The vulnerability was discovered by Philippe Caturegli and Mohamed Mahmoudi of Seralys during a third-party security review and responsibly disclosed to Quest Software on April 14, 2025. Quest released hotfixes on May 27, 2025, and Seralys published a high-level advisory on June 23, 2025. Detailed technical exploitation methodology and proof-of-concept code remain embargoed.

Three additional vulnerabilities were disclosed alongside CVE-2025-32975: CVE-2025-32976 (CVSS 8.8, 2FA bypass via TOTP validation flaw), CVE-2025-32977 (CVSS 9.6, unauthenticated backup file upload with weak signature validation), and CVE-2025-32978 (CVSS 7.5, unauthenticated license replacement causing DoS). All four are patched in the same hotfix releases.

Starting the week of March 9, 2026, Arctic Wolf's threat intelligence team observed active exploitation of CVE-2025-32975 against unpatched KACE SMA instances exposed to the internet. The observed attack chain proceeds as follows:

1. Initial Access: Attackers exploit CVE-2025-32975 to bypass SSO authentication and gain administrative access to the KACE SMA web interface without credentials.

2. Execution: Attackers abuse the legitimate KPluginRunProcess functionality within KACE SMA to execute arbitrary remote commands on the appliance. Analysis of KACE logs revealed Base64-encoded command payloads.

3. Command and Control: Attackers use curl to download files from the C2 server at 216.126.225.156, establishing persistent command-and-control communication channels.

4. Persistence: Attackers create additional administrative accounts via runkbot.exe (a legitimate Quest KACE process) and attempt to add these accounts to local and domain administrative groups.

5. Credential Access: Credential harvesting is performed using Mimikatz, with at least one instance observed where Mimikatz was disguised as asd.exe to evade detection.

The attacks primarily targeted education sector organizations. Arctic Wolf has not attributed the activity to a specific threat actor or nation-state, and stated they are unable to provide additional details regarding attacker identity or motivation at this time.

Organizations running KACE SMA should apply patches immediately (versions 13.0.385, 13.1.81, 13.2.183, 14.0.341 Patch 5, or 14.1.101 Patch 4). KACE SMA instances should never be directly exposed to the public internet; remote access should be restricted through VPN or firewall rules.

MITRE ATT&CK techniques used in TL-2026-0267

credential-access

T1003 OS Credential Dumping; T1555 Credentials from Password Stores

lateral-movement

T1021 Remote Services; T1210 Exploitation of Remote Services

defense-evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1070 Indicator Removal; T1078 Valid Accounts

execution

T1059 Command and Scripting Interpreter; T1569 System Services

command-and-control

T1071 Application Layer Protocol; T1105 Ingress Tool Transfer

discovery

T1082 System Information Discovery; T1087 Account Discovery

persistence

T1098 Account Manipulation; T1136 Create Account

initial-access

T1190 Exploit Public-Facing Application

impact

T1531 Account Access Removal

Affected products and versions in Quest KACE SMA Critical Authentication Bypass Actively

  • Quest Software — KACE Systems Management Appliance (SMA)
    Vulnerable versions: 13.0.x before 13.0.385; 13.1.x before 13.1.81; 13.2.x before 13.2.183; 14.0.x before 14.0.341; 14.1.x before 14.1.101
    Fixed in: 13.0.385; 13.1.81; 13.2.183; 14.0.341 (Patch 5); 14.1.101 (Patch 4)
  • Quest Software — KACE Asset Management Appliance
    Vulnerable versions: Versions prior to patched releases
    Fixed in: Contact Quest for specific patch versions
  • Quest Software — KACE Service Desk
    Vulnerable versions: Versions prior to patched releases
    Fixed in: Contact Quest for specific patch versions
  • Quest Software — KACE as a Service
    Vulnerable versions: Versions prior to patched releases
    Fixed in: Contact Quest for specific patch versions

Remediation for Quest KACE SMA Critical Authentication Bypass Actively

Patches

  • KACE SMA 13.0.385 (13.0.x hotfix)
  • KACE SMA 13.1.81 (13.1.x hotfix)
  • KACE SMA 13.2.183 (13.2.x hotfix)
  • KACE SMA 14.0.341 (Cumulative Patch 5)
  • KACE SMA 14.1.101 (Cumulative Patch 4)

Immediate actions

  • Apply KACE SMA patches immediately: 13.0.385, 13.1.81, 13.2.183, 14.0.341 (Patch 5), or 14.1.101 (Patch 4)
  • Remove KACE SMA instances from public internet exposure immediately
  • Restrict KACE SMA access to internal networks only via VPN or firewall rules
  • Audit KACE SMA administrative accounts for unauthorized additions
  • Review KACE SMA logs for KPluginRunProcess abuse and Base64-encoded command execution
  • Block C2 IP 216.126.225.156 at perimeter firewalls and proxy servers
  • Scan endpoints managed by KACE for Mimikatz artifacts (including asd.exe)

Workarounds

  • If patching is not immediately possible, restrict KACE SMA network access to trusted internal IPs only
  • Disable SSO authentication on KACE SMA until patch is applied
  • Monitor runkbot.exe and KPluginRunProcess for unusual command execution
  • Implement web application firewall rules to filter malicious SSO authentication requests

Longer-term hardening

  • Implement network segmentation to isolate management appliances from general user networks
  • Deploy EDR solutions with behavioral detection for credential harvesting tools
  • Enable multi-factor authentication for all administrative access to KACE SMA
  • Establish continuous vulnerability management program for infrastructure appliances
  • Implement SIEM monitoring for KACE SMA log anomalies and administrative account changes
  • Conduct regular penetration testing of management infrastructure

CVEs associated with Quest KACE SMA Critical Authentication Bypass Actively

CVE-2025-32975, CVE-2025-32976, CVE-2025-32977, CVE-2025-32978

Weaknesses (CWE) in Quest KACE SMA Critical Authentication Bypass Actively

CWE-287, CWE-288, CWE-347, CWE-306

Timeline of Quest KACE SMA Critical Authentication Bypass Actively

  • Philippe Caturegli and Mohamed Mahmoudi of Seralys submit initial vulnerability report for CVE-2025-32975 to Quest Software
  • Quest Software provides preliminary hotfix to Seralys for validation
  • Seralys confirms fix effectiveness for CVE-2025-32975
  • Quest publicly releases hotfixes for KACE SMA versions 13.0.385, 13.1.81, 13.2.183, 14.0.341 (Patch 5), and 14.1.101 (Patch 4)
  • Quest KACE Changelog published announcing resolution of CVE-2025-32975 through CVE-2025-32978
  • Seralys publishes high-level public disclosure on Full Disclosure mailing list; detailed PoC remains embargoed
  • NIST National Vulnerability Database publishes CVE-2025-32975 with CVSS 10.0 rating from CISA-ADP
  • NVD record for CVE-2025-32975 last modified with updated metadata
  • Arctic Wolf begins observing active exploitation of CVE-2025-32975 against unpatched, internet-exposed KACE SMA instances in education sector environments
  • Arctic Wolf publishes security advisory detailing observed exploitation activity including C2 communications, credential harvesting with Mimikatz, and administrative account creation
  • Belgium CCB publishes advisory confirming active exploitation and urging immediate patching of Quest KACE SMA
  • SecurityWeek and multiple security news outlets report on active exploitation of CVE-2025-32975 targeting education sector
  • As of 2026-05-29, CVE-2025-32975 (Quest KACE SMA, CVSS 10.0) is still active: CISA added it to KEV on 2026-04-20 (deadline 2026-05-04) and Arctic Wolf-observed exploitation of unpatched internet-facing instances continues. Mid-May 2026 Hunt.io/Security Affairs reporting revealed an MSP supply-chain breach exposing 60+ downstream orgs, with the unattributed campaign still expanding.

Sources cited for Quest KACE SMA Critical Authentication Bypass Actively

Threats related to Quest KACE SMA Critical Authentication Bypass Actively

Detection coverage for TL-2026-0267

As of 2026-03-21, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0267 across Splunk SPL, Microsoft KQL and Sigma, covering 12 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats