<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>cybercrime.club</title><link>https://cybercrime.club/tags/cve-2025-32975/</link><description>Infrastructure security news for people who build infrastructure.</description><generator>Hugo -- gohugo.io</generator><language>en-us</language><lastBuildDate>Tue, 21 Apr 2026 19:08:38 -0400</lastBuildDate><atom:link href="https://cybercrime.club/tags/cve-2025-32975/" rel="self" type="application/rss+xml"/><item><title>Quest KACE SMA CVE-2025-32975: CVSS 10.0 SSO Auth Bypass Added to CISA KEV as Admin Takeover Campaign Continues</title><link>https://cybercrime.club/posts/quest-kace-sma-cve-2025-32975-sso-auth-bypass-cisa-kev/</link><pubDate>Tue, 21 Apr 2026 19:08:38 -0400</pubDate><guid>https://cybercrime.club/posts/quest-kace-sma-cve-2025-32975-sso-auth-bypass-cisa-kev/</guid><description>CISA added CVE-2025-32975 — a CVSS 10.0 SSO authentication bypass in Quest KACE Systems Management Appliance — to the KEV catalog on April 20, 2026. Federal agencies must patch by May 4. Exploitation has been in progress since March.</description><category>vulnerabilities</category></item></channel></rss>