CVE-2025-71257Disclosure(bmc / footprints)

HIGHCVSS 9.1 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch bmc footprints systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts

Recommended action window: Immediate (within 24h)

NVD description

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain an authentication bypass vulnerability due to improper enforcement of security filters on restricted REST API endpoints and servlets. Unauthenticated remote attackers can bypass access controls to invoke restricted functionality and gain unauthorized access to application data and modify system resources. The following hotfixes remediate the vulnerability: 20.20.02, 20.20.03.002, 20.21.01.001, 20.21.02.002, 20.22.01, 20.22.01.001, 20.23.01, 20.23.01.002, and 20.24.01.

6.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • footprints

Threat summary

  • Active exploitation appears in 1 classified signals
  • Exploit tooling references are present in monitored signal
  • Patch or workaround signal is available
  • 8 mentions across 5 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • General: 2 classified signals
  • Peaked 4d ago at 2 mentions (2026-03-18); latest day: 1
  • 8 total mentions across 5 days

Affected systems

Vendors
Products
footprints

Deep dive

Activity timeline8 mentions / 5d
01122Mentions · 2026-03-18: 2Mentions · 2026-03-19: 1Mentions · 2026-03-20: 2Mentions · 2026-03-23: 2Mentions · 2026-03-24: 1Exploit Tool / Code · 2026-03-23: 1Active Exploitation · 2026-03-23: 1Patch / Workaround · 2026-03-24: 1Technical Details · 2026-03-18: 1Technical Details · 2026-03-23: 2Technical Details · 2026-03-24: 103-1803-1903-2003-2303-24
Signal classification4 categories
Disclosure
450.0%
General
225.0%
Active Exploitation
112.5%
Patch
112.5%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-182
Disclosure1General1
2026-03-191
Disclosure1
2026-03-202
Disclosure1General1
2026-03-232
Active Exploitation1Disclosure1
2026-03-241
Patch1
Full discourse8 posts
  • ET Labs@ET_Labs
    General

    19 new OPEN, 30 new PRO (19 + 11) BMC FootPrints (CVE-2025-71257, CVE-2025-71258, CVE-2025-71259, CVE-2025-21760), LandUpdate808, Lumma Stealer, Proxy Service Domains, SolarWinds (CVE-2025-40554), UNK_VaporVibes, XWorm, ZPHP https://community.emergingthreats.net/t/ruleset-update-summary-2026-03-18-v11151/3236

    Post summary

    The post lists several new CVEs and malware names but offers no additional technical, exploit, or mitigation details.

    03032416
    5.7K followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    🚨🚨🚨 CVE-2025-71257 - Authentication Bypass CVE-2025-71258 - SSRF CVE-2025-71259 - SSRF CVE-2025-71260 - Deserialization of Untrusted Data (RCE) The Most Organized Threat Actors Use Your ITSM (BMC FootPrints Pre-Auth Remote Code Execution Chains) https://labs.watchtowr.com/thanks-itsms-threat-actors-have-never-been-so-organized-bmc-footprints-pre-auth-remote-code-execution-chains/

    Post summary

    The post announces newly reported CVEs and briefly describes their nature, but offers no proof‑of‑concept, exploit code, active exploitation evidence, or patch guidance.

    01042706
    6.7K followersView on X
  • bigmacd@bigmacd16684
    Active Exploitation

    🚨 Critical vulnerabilities in BMC FootPrints: Auth bypass (CVE-2025-71257), 2 SSRF bugs (CVE-2025-71258, CVE-2025-71259), Java deserialization RCE (CVE-2025-71260). Exploited by watchTowr for pre-auth R

    Post summary

    WatchTowr has reportedly leveraged multiple critical CVEs in BMC FootPrints—auth bypass, SSRF, and Java deserialization RCE—demonstrating active exploitation in the wild.

    10000144
    3 followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: A #pre-auth #RCE chain affecting #BMC FootPrints (ITSM) allows full compromise via chained flaws: #CVE-2025-71257, #CVE-2025-71258, #CVE-2025-71259, #CVE-2025-71260.#ITSM platforms are frequent ransomware targets. #Patch #Patch #Patch https://labs.watchtowr.com/thanks-itsms-threat-actors-have-never-been-so-organized-bmc-footprints-pre-auth-remote-code-execution-chains/

    Post summary

    BMC FootPrints suffers a pre‑auth RCE chain spanning CVE‑2025‑71257 to CVE‑2025‑71260; patches are available and urgently recommended.

    00000349
    7.2K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-71257 BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain an authentication bypass vulnerability due to improper enforcement of security filters on restricte… https://www.cve.org/CVERecord?id=CVE-2025-71257

    Post summary

    An authentication bypass vulnerability (CVE-2025-71257) affects BMC FootPrints ITSM versions 20.20.02–20.24.01.001 due to improper enforcement of security filters, but no exploit, patch, or active exploitation details are provided.

    00000115
    56.8K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    General

    🚨 CVE-2025-71257 - medium 🚨 BMC FootPrints - Authentication Bypass > BMC FootPrints versions 20.20.02 through 20.24.01.001 contain an authentication bypas... 👾 https://cloud.projectdiscovery.io/library/CVE-2025-71257 @pdnuclei #NucleiTemplates #cve

    Post summary

    The post highlights CVE‑2025‑71257 as an authentication bypass in BMC FootPrints, providing only minimal information and a general link to a library, without detailed technical or exploitation specifics.

    00000237
    900 followersView on X
  • RedPacket Security@RedPacketSec
    Disclosure

    CVE Alert: CVE-2025-71257 - BMC Software, Inc. - FootPrints - https://www.redpacketsecurity.com/cve-alert-cve-2025-71257-bmc-software-inc-footprints/ #OSINT #ThreatIntel #CyberSecurity #cve-2025-71257 #bmc-software-inc #footprints

    Post summary

    An alert has been posted for CVE-2025-71257 affecting BMC FootPrints; the post provides no additional details on PoC, exploitation, patches, or technical specifics.

    00000240
    3.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-71257 Authentication Bypass Vulnerability in BMC FootPrints ITSM Versions 20.20.02-20.24.01.001 https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-71257

    Post summary

    The text announces that BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain an authentication bypass vulnerability (CVE‑2025‑71257), but provides no additional details or context.

    00000181
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appbmcfootprints---

Explore more