ET Labs@ET_LabsGeneral
A routine update listing new CVEs (BMC FootPrints, SolarWinds, etc.) without providing PoC, exploit, patch, or active exploitation details.
Autumn Good@autumn_good_35Disclosure
The post lists four new CVEs with associated vulnerability types and links to a lab article that outlines threat actor activity targeting BMC FootPrints.
bigmacd@bigmacd16684Active Exploitation
BMC FootPrints suffers critical flaws—an authentication bypass, two SSRF vulnerabilities, and a Java deserialization RCE—that have reportedly been exploited by the entity watchTowr pre-authentication.
pdnuclei-bot@pdnuclei_botDisclosure
The post announces the discovery of a high‑severity SSRF vulnerability (CVE‑2025‑71258) in BMC FootPrints versions 20.20.02 to 20.24.01.001, providing basic technical details but no PoC, exploit code, or patch information.
CCB Alert@CCBalertDisclosure
The tweet announces a pre‑authentication RCE chain affecting BMC FootPrints with four CVEs, urges patching, but provides no PoC, exploit code, or evidence of active exploitation.
CVE@CVEnewDisclosure
The statement discloses CVE-2025-71258, indicating a blind SSRF flaw in BMC FootPrints ITSM’s searchWeb API, but contains no PoC, exploit, patch, or active exploitation details.
Vulmon Vulnerability Feed@VulmonFeedsGeneral
The tweet simply announces CVE‑2025‑71258 as a blind SSRF in BMC FootPrints ITSM, with no additional details on PoC, exploitation, or remediation.