Quest KACE SMA flaw CVE-2025-32975: when one unpatched tool opens the door to 60 organizations

2026-05-13T14:51:44Zdf407dfef52bd1f8cdba9d90af75ce95d75cbdbd4140da3209802cc6fb6dce0c
FortinetInstructureQuest-KACESailPointTrickMoai-threatsandroid-malwarecPaneldata-breachendpoint-managementexploitationmalwareransomwaresupply-chainvulnerabilitiesweb-hosting

What happened

Multiple high-impact security events: a critical flaw in Quest KACE SMA (CVE-2025-32975) risks full compromise of managed endpoints; threat actors are actively exploiting cPanel CVE-2026-41940 (CVSS 9.3) to deploy a Filemanager backdoor; Fortinet patched critical vulnerabilities including CVE-2026-44277 in FortiAuthenticator. Significant breaches and incidents were reported — Instructure reportedly negotiated with extortionists after a Canvas data theft, BWH Hotels disclosed months-long access to reservation data, and SailPoint disclosed a GitHub repository breach. Malware developments include

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
df407dfef52bd1f8cdba9d90af75ce95d75cbdbd4140da3209802cc6fb6dce0c
Enrichment time
2026-05-13T14:51:44Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.