Quest KACE SMA Systems Hacked via Critical CVE-2025-32975 Vulnerability. Devices Unpatched Were Targeted.
Mar 23, 2026 // 11:23 - Niko Dunn


Arctic Wolf reports that malicious actors are likely exploiting a critical security vulnerability in Quest KACE Systems Management Appliance (SMA).

The cybersecurity firm stated it detected suspicious behavior in customer environments starting the week of March 9, 2026, suggesting exploitation of CVE-2025-32975 on vulnerable, internet-facing unpatched SMA systems. The attackers’ ultimate objectives are currently unknown.

CVE-2025-32975 (CVSS score: 10.0) is an authentication flaw that allows unauthorized individuals to pose as valid users, potentially leading to complete administrative account compromise. Quest released a fix for this vulnerability in May 2025.

Arctic Wolf’s investigation indicates that the attackers are exploiting the vulnerability to take control of administrative accounts and remotely inject Base64-encoded code from an external server (216.126.225[.]156) using the curl command.

The attackers then created new administrative accounts using “runkbot.exe,” an SMA Agent background process for script execution and installation management. Modifications to the Windows Registry via a PowerShell script were also observed, possibly for persistence or system configuration.

Further actions carried out by the attackers include the following:

  • Stealing credentials with Mimikatz.
  • Performing system reconnaissance by listing logged-in users and administrator accounts and executing “net time” and “net group” commands.
  • Gaining remote desktop protocol (RDP) access to backup systems (Veeam, Veritas) and domain controllers.

To mitigate this threat, administrators should install the latest updates and avoid exposing SMA systems directly to the internet. The vulnerability is resolved in versions 13.0.385, 13.1.81, 13.2.183, 14.0.341 (Patch 5), and 14.1.101 (Patch 4).

#critical  #cve-2025-32975  #devices  #hacked  #kace  #news  #quest  #sma  #systems  #targeted  #unpatched  #via  #vulnerability  #were   —   News