CVE-2025-32975: Quest KACE SMA SSO Authentication Bypass Enables Admin Takeover — Actively Exploited — Threadlinqs Intelligence
As of 2026-05-30, CVE-2025-32975: Quest KACE SMA SSO Authentication Bypass Enables Admin Takeover — Actively Exploited is a critical-severity vulnerability threat attributed to a N/A-nexus actor, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 15 indicators of compromise.
Threat ID: TL-2026-0272 · Severity: CRITICAL · CVSS: 10 · Status: MONITORING · Category: VULNERABILITY
Attribution: N/A · UNKNOWN
Critical authentication bypass vulnerability (CVSS 10.0) in Quest KACE Systems Management Appliance (SMA) SSO mechanism allows unauthenticated remote attackers to impersonate legitimate users and
CVE-2025-32975 is a critical improper authentication vulnerability (CWE-287) in the Single Sign-On (SSO) authentication handler of Quest KACE Systems Management Appliance (SMA). The flaw allows unauthenticated attackers to bypass SSO authentication entirely and impersonate any legitimate user — including administrators — without valid credentials, passwords, or authentication tokens.
The vulnerability carries the maximum CVSS 3.1 base score of 10.0 (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H), reflecting its network-accessible attack vector, low complexity, zero privilege/interaction requirements, and changed scope with full confidentiality, integrity, and availability impact. Successful exploitation grants complete administrative control over the KACE SMA appliance, which serves as centralized endpoint management infrastructure across enterprise environments.
The vulnerability was responsibly disclosed by security researchers Philippe Caturegli and Mohamed Mahmoudi of Seralys Research Team on April 14, 2025. Quest Software developed and validated a hotfix between May 8-17, 2025, with public hotfix release on May 27, 2025. High-level disclosure was published on June 23, 2025. The NVD published the entry on June 24, 2025.
Despite patches being available since May 2025, Arctic Wolf began observing active exploitation of unpatched, internet-exposed KACE SMA instances starting the week of March 9, 2026. The observed attack chain involves: (1) authentication bypass via CVE-2025-32975 on internet-facing SMA instances, (2) seizure of administrative account control, (3) abuse of KPluginRunProcess functionality to execute remote commands, (4) downloading Base64-encoded payloads from the external server 216.126.225.156 via curl, (5) creation of additional administrative accounts using runkbot.exe (the KACE SMA Agent background process), (6) Windows Registry modifications for persistence, (7) deployment of Mimikatz (disguised as asd.exe) for credential harvesting from LSASS memory, (8) reconnaissance via net time, net group, and administrator/user enumeration commands, and (9) lateral movement via RDP to backup infrastructure (Veeam, Veritas) and Active Directory domain controllers.
Quest KACE SMA is widely deployed across enterprises for systems management, software distribution, patching, and asset inventory. Compromise of KACE SMA infrastructure provides attackers with a privileged position to pivot across the entire managed endpoint fleet, access credential stores, and compromise backup and domain controller infrastructure. The targeting of backup systems (Veeam, Veritas) is consistent with pre-ransomware operational patterns.
Affected versions span the 13.x and 14.x branches: 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (Patch 4). Note that upgrades from 14.0.341 to 14.1.95 are not supported — administrators must install 14.1.101 directly. Additionally, the 13.x security hotfix must be re-applied after every full 13.x upgrade. A known issue exists where KACE Go app users cannot login after applying the security patch.
Target sectors: enterprise, government, education, healthcare, financial, technology, manufacturing
Target regions: North America, Europe, Asia-Pacific, Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 15 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2025-32975, T1190, T1078, T1078, T1136, T1059, T1059, T1003, T1036, T1112, T1087