惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
美团技术团队
Last Week in AI
Last Week in AI
WordPress大学
WordPress大学
博客园 - 三生石上(FineUI控件)
博客园 - 聂微东
雷峰网
雷峰网
阮一峰的网络日志
阮一峰的网络日志
博客园 - 叶小钗
IT之家
IT之家
Google DeepMind News
Google DeepMind News
D
Docker
J
Java Code Geeks
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Apple Machine Learning Research
Apple Machine Learning Research
博客园 - 【当耐特】
V
V2EX
Hugging Face - Blog
Hugging Face - Blog
博客园 - Franky
月光博客
月光博客
宝玉的分享
宝玉的分享
酷 壳 – CoolShell
酷 壳 – CoolShell
aimingoo的专栏
aimingoo的专栏
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More

Cyberwarzone

LinkedIn Sued Over Browser Extension Scanning Why Cyberwarfare Uses Ambiguity and Delayed Attribution as Pressure Why Cyberwarfare Pressures Trusted Access and Account Recovery Paths Why Cyberwarfare Keeps Pressuring Recovery Paths and Fallback Systems Why Cyberwarfare Keeps Pressuring Shared Service Providers Why Cyberwarfare Pressures Industry Clusters Why Cyberwarfare Turns Nearby Economies Into Spillover Zones Why Cyberwarfare Forces Firms to Scan Networks Early Why Cyberwarfare Targets Crisis Messaging Systems Why Cyberwarfare Keeps Pressuring Energy Networks Why Cyberwarfare Keeps Pressuring Communications Networks Why Cyberwarfare Keeps Pressuring Shipping and Logistics Networks Why Cyberwarfare Keeps Pressuring Banks and Financial Networks Why Endpoint Management Systems Are Becoming Cyberwarfare Choke Points Why Cyberwarfare Targets Healthcare and Medical Supply Chains Why Cyberwarfare Increasingly Exploits Trusted Civilian Apps Why Cyberwarfare Hits Civilian Companies First Handala Rebounds After FBI Seizure, Exposing Iran Cyberwar Resilience Top 10 Cyber Escalation Risks Security Leaders Should Understand Top 10 Questions to Ask Before Calling an Incident Cyberwarfare Top 10 Cyber Deterrence Problems Security Leaders Should Understand Top 10 OT and ICS Risks in Modern Cyberwarfare Top 10 Cyberwarfare Doctrine Ideas Security Leaders Should Understand Top 10 Attribution Problems in State-Linked Cyber Operations Iran Cyberwar: Identity Systems Become the Target Iran Cyberwar Shifts to Spillover, Retaliation, and Control Top 10 Critical Infrastructure Sectors Most Exposed in Cyberwarfare Top 10 Below-Threshold Cyber Operations States Use Top 10 Differences Between Cyberwarfare and Cyber Espionage Top 10 Signs a Cyber Campaign Is Pre-Positioning for Future Conflict
Critical Quest KACE SMA RCE (CVE-2025-32975) Under Attack
Peter Chofield · 2026-03-24 · via Cyberwarzone

Threat actors are actively exploiting CVE-2025-32975, a critical path traversal vulnerability in Quest KACE Systems Management Appliance (SMA), to achieve unauthenticated remote code execution (RCE). The flaw carries a maximum CVSS v3.1 score of 10.0, indicating its severe impact.

The vulnerability was discovered and disclosed by Assetnote researchers on February 28, 2026. Quest subsequently released patches for the affected software on March 18, 2026.

CVE-2025-32975: Unauthenticated Remote Code Execution Details

CVE-2025-32975 is a path traversal vulnerability located in the /agent/agentless_update.php endpoint of the Quest KACE SMA. This flaw allows an unauthenticated attacker to upload arbitrary files to publicly accessible locations on the appliance. By uploading a malicious PHP file, attackers can execute arbitrary code with root privileges.

The vulnerability can be leveraged by unauthenticated attackers to execute arbitrary code with root privileges on affected KACE SMA appliances. The impact of this vulnerability is severe, as it allows full control over the appliance, which often manages a large number of endpoints in an organization.

— Assetnote researchers

The exploit chain bypasses authentication mechanisms, granting attackers full control over the compromised appliance. Given that KACE SMA devices manage numerous endpoints within an organization, successful exploitation poses a significant risk of broader network compromise, similar to other unauthenticated arbitrary file upload vulnerabilities.

Affected Versions and Remediation

The vulnerability impacts Quest KACE SMA versions 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, and 12.0. Users are strongly advised to update their appliances to version 12.1 or later to mitigate the risk of exploitation and ensure proof of remediation.

About the Author

Peter Chofield Avatar

Peter Chofield

Passionate about cybersecurity, Peter dedicates his days to reading, analyzing, and writing about the trends shaping the online world.