惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Vercel News
Vercel News
博客园 - 司徒正美
大猫的无限游戏
大猫的无限游戏
Last Week in AI
Last Week in AI
V
Visual Studio Blog
阮一峰的网络日志
阮一峰的网络日志
小众软件
小众软件
宝玉的分享
宝玉的分享
Apple Machine Learning Research
Apple Machine Learning Research
美团技术团队
WordPress大学
WordPress大学
博客园 - 聂微东
人人都是产品经理
人人都是产品经理
罗磊的独立博客
The Cloudflare Blog
V
V2EX
月光博客
月光博客
有赞技术团队
有赞技术团队
Y
Y Combinator Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
GbyAI
GbyAI
博客园 - 【当耐特】
T
Tailwind CSS Blog

Cyberwarzone

LinkedIn Sued Over Browser Extension Scanning Why Cyberwarfare Uses Ambiguity and Delayed Attribution as Pressure Why Cyberwarfare Pressures Trusted Access and Account Recovery Paths Why Cyberwarfare Keeps Pressuring Recovery Paths and Fallback Systems Why Cyberwarfare Keeps Pressuring Shared Service Providers Why Cyberwarfare Pressures Industry Clusters Why Cyberwarfare Turns Nearby Economies Into Spillover Zones Why Cyberwarfare Forces Firms to Scan Networks Early Why Cyberwarfare Targets Crisis Messaging Systems Why Cyberwarfare Keeps Pressuring Energy Networks Why Cyberwarfare Keeps Pressuring Communications Networks Why Cyberwarfare Keeps Pressuring Shipping and Logistics Networks Why Cyberwarfare Keeps Pressuring Banks and Financial Networks Why Endpoint Management Systems Are Becoming Cyberwarfare Choke Points Why Cyberwarfare Targets Healthcare and Medical Supply Chains Why Cyberwarfare Increasingly Exploits Trusted Civilian Apps Why Cyberwarfare Hits Civilian Companies First Handala Rebounds After FBI Seizure, Exposing Iran Cyberwar Resilience Top 10 Cyber Escalation Risks Security Leaders Should Understand Top 10 Questions to Ask Before Calling an Incident Cyberwarfare Top 10 Cyber Deterrence Problems Security Leaders Should Understand Top 10 OT and ICS Risks in Modern Cyberwarfare Top 10 Cyberwarfare Doctrine Ideas Security Leaders Should Understand Top 10 Attribution Problems in State-Linked Cyber Operations Iran Cyberwar: Identity Systems Become the Target Iran Cyberwar Shifts to Spillover, Retaliation, and Control Top 10 Critical Infrastructure Sectors Most Exposed in Cyberwarfare Top 10 Below-Threshold Cyber Operations States Use Top 10 Differences Between Cyberwarfare and Cyber Espionage Top 10 Signs a Cyber Campaign Is Pre-Positioning for Future Conflict
Critical Quest KACE SMA RCE (CVE-2025-32975) Under Attack
Peter Chofield · 2026-03-24 · via Cyberwarzone

Threat actors are actively exploiting CVE-2025-32975, a critical path traversal vulnerability in Quest KACE Systems Management Appliance (SMA), to achieve unauthenticated remote code execution (RCE). The flaw carries a maximum CVSS v3.1 score of 10.0, indicating its severe impact.

The vulnerability was discovered and disclosed by Assetnote researchers on February 28, 2026. Quest subsequently released patches for the affected software on March 18, 2026.

CVE-2025-32975: Unauthenticated Remote Code Execution Details

CVE-2025-32975 is a path traversal vulnerability located in the /agent/agentless_update.php endpoint of the Quest KACE SMA. This flaw allows an unauthenticated attacker to upload arbitrary files to publicly accessible locations on the appliance. By uploading a malicious PHP file, attackers can execute arbitrary code with root privileges.

The vulnerability can be leveraged by unauthenticated attackers to execute arbitrary code with root privileges on affected KACE SMA appliances. The impact of this vulnerability is severe, as it allows full control over the appliance, which often manages a large number of endpoints in an organization.

— Assetnote researchers

The exploit chain bypasses authentication mechanisms, granting attackers full control over the compromised appliance. Given that KACE SMA devices manage numerous endpoints within an organization, successful exploitation poses a significant risk of broader network compromise, similar to other unauthenticated arbitrary file upload vulnerabilities.

Affected Versions and Remediation

The vulnerability impacts Quest KACE SMA versions 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, and 12.0. Users are strongly advised to update their appliances to version 12.1 or later to mitigate the risk of exploitation and ensure proof of remediation.

About the Author

Peter Chofield Avatar

Peter Chofield

Passionate about cybersecurity, Peter dedicates his days to reading, analyzing, and writing about the trends shaping the online world.