HIGHVulnerability
Verified
Global

CISA KEV: Quest KACE Systems Management Appliance (SMA) — Quest KACE Systems Management Appliance (SMA) Improper Authentication Vulnerability

·Source: CISA KEV

Updated:

Executive Summary

Quest KACE Systems Management Appliance (SMA) contains an improper authentication vulnerability that could allow attackers to impersonate legitimate users without valid credentials.

Analysis

Quest KACE Systems Management Appliance (SMA) contains an improper authentication vulnerability that could allow attackers to impersonate legitimate users without valid credentials. Added to CISA Known Exploited Vulnerabilities catalog on 2026-04-20. Remediation due: 2026-05-04.

Indicators of Compromise (1)

CVE (1)
CVE-2025-32975
Source Attribution

Originally published by CISA KEV on Apr 20, 2026. Verified by: CISA.

Related Threats

MEDIUMVulnerabilityNEW

NC: Possible cyberattack hits Wake election software vendor, leaving poll workers’ data exposed

Caroline Yaffa reports: The Wake County Board of Elections is suspending its use of a software vendor after it reported a possible cyberattack. There’s no evidence that voting machines, ballots, voter registration records or systems used to count votes were affected, according to the county board. But the incident could have exposed information about people... Source

DataBreaches.net
CRITICALVulnerability

NVD CRITICAL: CVE-2026-73053 — SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in th...

SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in the unicode2Emoji function that fails to sanitize codepoint branch output. Attackers can craft document icons with hex-encoded markup that executes in the renderer with Node integration enabled, achieving arbitrary code execution on the host system.

CVE-2026-73053
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-73052 — SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and...

SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and interpolates them directly into option elements via innerHTML in the sort menu. Attackers can inject markup by renaming a database field to execute arbitrary JavaScript when users open the sort menu, with Node integration enabled in the desktop client enabling code execution.

CVE-2026-73052
NIST NVD