Critical Quest KACE Vulnerability Potentially Exploited in Attacks
2026-03-21T13:24:04Z•32a1d9e9e1c918c0c3e177dfc35bfe226b13e70d7d2db6705281e7c466451170
CVE-2025-32975ClaudeGentlemen ransomwareHandalaKVMLangflowMagento defacementNavia breachQuest KACEdata breacheducation sectorexploitationunauthenticated remote code execution
What happened
SecurityWeek reports a critical Quest KACE vulnerability (CVE-2025-32975) that may have been exploited in attacks targeting the education sector. The feed also highlights other notable incidents: a critical Langflow flaw actively exploited shortly after disclosure leading to unauthenticated remote code execution, an ongoing Magento site defacement campaign, a Navia data breach affecting ~2.7M, US takedown/seizure of Handala-affiliated domains, and mentions of vulnerabilities in KVM devices and Claude-related issues. Organizations using Quest KACE, Langflow, and affected e‑commerce platforms/VM
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityweek
- Record identifier
- 32a1d9e9e1c918c0c3e177dfc35bfe226b13e70d7d2db6705281e7c466451170
- Enrichment time
- 2026-03-21T13:24:04Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.