🔴
CISA KEV Alert — Active Real-World Exploitation Confirmed
This vulnerability is in the CISA Known Exploited Vulnerabilities catalog and is being actively exploited right now.
Quest KACE Systems Management Appliance Authentication Bypass (CVE-2025-32975) | MSSP Advisory
High🔴 KEV ALERT
DateMay 6, 2026
CVECVE-2025-32975
CVSS Score10.0
Affectedkace_systems_management_appliance
📋Executive Summary
CISA added CVE-2025-32975 to the Known Exploited Vulnerabilities catalog, targeting Quest KACE Systems Management Appliances with an authentication bypass that allows attackers to impersonate legitimate users without credentials. Government agencies have until May 2026 to patch or discontinue use, signaling active exploitation is already happening.
⚠️Why It Matters for MSSPs
Your RMM and client management infrastructure becomes a direct target since Quest KACE appliances manage endpoints across multiple client networks, and authentication bypass means attackers can masquerade as legitimate administrators. Client contracts likely require you to alert them about threats affecting their managed infrastructure, making this both a technical emergency and a compliance obligation.
✅Recommended Action
Audit your stack and all client environments for Quest KACE SMA deployments within 24 hours, immediately apply vendor patches where available, and send client notifications about this vulnerability with specific remediation timelines. If patches are not available, prepare contingency plans for alternative management solutions.
🔒Get your first advisory free →
Partner content — get access free
The recommended action is included in your white-labeled advisory — ready to send to clients under your name.
🏷️Threat Category
Identity Access
Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.