CISA Known Exploited Vulnerability
This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.
Remediation Deadline: May 4, 2026
Description
Referenced in article: Critical Quest KACE Vulnerability Potentially Exploited in Attacks
EPSS — Exploit Probability
Higher than 37.7% of all CVEs
Required Action
https://support.quest.com/kb/4379499/quest-response-to-kace-sma-vulnerabilities-cve-2025-32975-cve-2025-32976-cve-2025-32977-cve-2025-32978 ; https://nvd.nist.gov/vuln/detail/CVE-2025-32975
Related Articles (2)
Critical Quest KACE Vulnerability Potentially Exploited in Attacks
The vulnerability is tracked as CVE-2025-32975 and it may have been exploited in attacks against the education sector.
Mar 21, 2026
Hackers Exploit CVE-2025-32975 (CVSS 10.0) to Hijack Unpatched Quest KACE SMA Systems
CVE-2025-32975 exploited since March 2026 on unpatched KACE SMA systems, enabling admin takeover and payload delivery.
Mar 23, 2026
Risk Assessment
ELEVATEDDetails
- Severity
- Info
- EPSS
- 0.2%
- CISA KEV
- Yes
- Ransomware
- Unknown
- Articles
- 2
Timeline
Published
Mar 28, 2026
Added to KEV
Apr 20, 2026
Remediation Due
May 4, 2026