Attackers are actively exploiting CVE-2025-32975, a CVSS 10.0 authentication bypass flaw in Quest KACE Systems Management Appliance (SMA), to take over unpatched, internet-exposed systems and gain administrative access without valid credentials. Arctic Wolf said it observed malicious activity beginning the week of March 9, 2026, with exploitation targeting KACE SMA SSO authentication handling on affected versions through 14.1. Quest had previously released patches and hotfixes, but exposed appliances that remain unpatched are being treated as high-risk for full administrative compromise.
Observed intrusions included remote command execution through KPluginRunProcess, payload retrieval from 216.126.225[.]156, creation of rogue administrator accounts via runkbot.exe, Windows Registry changes using PowerShell, credential theft with Mimikatz, reconnaissance, and RDP access to backup infrastructure and domain controllers. Researchers assessed the activity as likely opportunistic and urged organizations to immediately update to fixed versions, remove SMA instances from direct internet exposure, hunt for unauthorized admin accounts, rotate KACE administrative credentials, and assume any unpatched public-facing appliance may already be compromised.

See which actors are running it and whether you're in range.
4 events from the most recent confirmed update back to the earliest known activity.
Arctic Wolf publicly reported suspected active exploitation of CVE-2025-32975 in unpatched Quest KACE SMA systems and warned that exposed appliances should be treated as potentially compromised. The disclosure included recommendations to patch immediately, remove direct internet exposure, hunt for rogue admin accounts, and rotate KACE administrative credentials.
Following access, attackers downloaded Base64-encoded payloads from 216.126.225[.]156, created rogue admin accounts via runkbot.exe, modified the Windows Registry with PowerShell, harvested credentials with Mimikatz, and conducted reconnaissance. The intrusions also included RDP access to backup infrastructure and domain controllers.
Arctic Wolf observed suspected in-the-wild exploitation beginning the week of March 9, 2026, targeting unpatched, internet-facing Quest KACE SMA appliances in customer environments. The activity appeared opportunistic and resulted in takeover of administrative accounts and remote command execution.
Quest released fixed versions and hotfixes for the maximum-severity authentication bypass vulnerability CVE-2025-32975 affecting KACE Systems Management Appliance, including supported branches and versions through 14.1. The flaw could allow unauthenticated attackers to impersonate legitimate users and gain administrative access.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.