Oops! Quest KACE Two-Factor Authentication Takes a Nap: CVE-2025-32976 Exploit Unveiled!

Quest KACE SMA has a 2FA bypass flaw, allowing authenticated users to skip TOTP-based security. It’s like being on a diet and finding a loophole in the cookie jar! Versions 13.0.385 and up have the fix. So, update now and keep your security as tight as your favorite pair of jeans!

Pro Dashboard

Hot Take:

Looks like Quest KACE SMA took the “two” out of two-factor authentication! No need to panic though, Quest is on it like a patch on a quilt. Just remember, in the world of cybersecurity, two-factor is better than no-factor, but only if it actually works!

Key Points:

  • Quest KACE SMA had a vulnerability allowing bypass of two-factor authentication.
  • Severity of the flaw is high, with a CVSS score of 8.8.
  • Fixes have been released in several patched versions of the software.
  • Initial discovery was in April 2025 by Seralys researchers.
  • Quest has coordinated disclosure and issued a public patch.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?