Critical Quest KACE Vulnerability Potentially Exploited in Attacks

2026-03-21T13:24:04Z32a1d9e9e1c918c0c3e177dfc35bfe226b13e70d7d2db6705281e7c466451170
CVE-2025-32975ClaudeGentlemen ransomwareHandalaKVMLangflowMagento defacementNavia breachQuest KACEdata breacheducation sectorexploitationunauthenticated remote code execution

What happened

SecurityWeek reports a critical Quest KACE vulnerability (CVE-2025-32975) that may have been exploited in attacks targeting the education sector. The feed also highlights other notable incidents: a critical Langflow flaw actively exploited shortly after disclosure leading to unauthenticated remote code execution, an ongoing Magento site defacement campaign, a Navia data breach affecting ~2.7M, US takedown/seizure of Handala-affiliated domains, and mentions of vulnerabilities in KVM devices and Claude-related issues. Organizations using Quest KACE, Langflow, and affected e‑commerce platforms/VM

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityweek
Record identifier
32a1d9e9e1c918c0c3e177dfc35bfe226b13e70d7d2db6705281e7c466451170
Enrichment time
2026-03-21T13:24:04Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.