Oops! Quest KACE Two-Factor Authentication Takes a Nap: CVE-2025-32976 Exploit Unveiled!
Quest KACE SMA has a 2FA bypass flaw, allowing authenticated users to skip TOTP-based security. It’s like being on a diet and finding a loophole in the cookie jar! Versions 13.0.385 and up have the fix. So, update now and keep your security as tight as your favorite pair of jeans!

Hot Take:
Looks like Quest KACE SMA took the “two” out of two-factor authentication! No need to panic though, Quest is on it like a patch on a quilt. Just remember, in the world of cybersecurity, two-factor is better than no-factor, but only if it actually works!
Key Points:
- Quest KACE SMA had a vulnerability allowing bypass of two-factor authentication.
- Severity of the flaw is high, with a CVSS score of 8.8.
- Fixes have been released in several patched versions of the software.
- Initial discovery was in April 2025 by Seralys researchers.
- Quest has coordinated disclosure and issued a public patch.
Already a member? Log in here