CVE-2025-71258Disclosure(bmc / footprints)

MEDIUMCVSS 7.1 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch bmc footprints systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind server-side request forgery vulnerability in the searchWeb API component that allows authenticated attackers to cause the server to initiate arbitrary outbound requests. Attackers can exploit improper URL validation to perform internal network scanning or interact with internal services, impacting system availability. The following hotfixes remediate the vulnerability: 20.20.02, 20.20.03.002, 20.21.01.001, 20.21.02.002, 20.22.01, 20.22.01.001, 20.23.01, 20.23.01.002, and 20.24.01.

5.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • footprints

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 7 mentions across 5 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 4 classified signals
  • General: 2 classified signals
  • Peaked 4d ago at 2 mentions (2026-03-18); latest day: 1
  • 7 total mentions across 5 days

Affected systems

Vendors
Products
footprints

Deep dive

Activity timeline7 mentions / 5d
01122Mentions · 2026-03-18: 2Mentions · 2026-03-19: 1Mentions · 2026-03-20: 1Mentions · 2026-03-23: 2Mentions · 2026-03-24: 1PoC Mentioned / Linked · 2026-03-18: 1Active Exploitation · 2026-03-23: 1Patch / Workaround · 2026-03-24: 1Technical Details · 2026-03-18: 1Technical Details · 2026-03-19: 1Technical Details · 2026-03-20: 1Technical Details · 2026-03-23: 2Technical Details · 2026-03-24: 103-1803-1903-2003-2303-24
Signal classification3 categories
Disclosure
457.1%
General
228.6%
Active Exploitation
114.3%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-182
Disclosure1General1
2026-03-191
General1
2026-03-201
Disclosure1
2026-03-232
Active Exploitation1Disclosure1
2026-03-241
Disclosure1
Full discourse7 posts
  • ET Labs@ET_Labs
    General

    19 new OPEN, 30 new PRO (19 + 11) BMC FootPrints (CVE-2025-71257, CVE-2025-71258, CVE-2025-71259, CVE-2025-21760), LandUpdate808, Lumma Stealer, Proxy Service Domains, SolarWinds (CVE-2025-40554), UNK_VaporVibes, XWorm, ZPHP https://community.emergingthreats.net/t/ruleset-update-summary-2026-03-18-v11151/3236

    Post summary

    A routine update listing new CVEs (BMC FootPrints, SolarWinds, etc.) without providing PoC, exploit, patch, or active exploitation details.

    03032416
    5.7K followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    🚨🚨🚨 CVE-2025-71257 - Authentication Bypass CVE-2025-71258 - SSRF CVE-2025-71259 - SSRF CVE-2025-71260 - Deserialization of Untrusted Data (RCE) The Most Organized Threat Actors Use Your ITSM (BMC FootPrints Pre-Auth Remote Code Execution Chains) https://labs.watchtowr.com/thanks-itsms-threat-actors-have-never-been-so-organized-bmc-footprints-pre-auth-remote-code-execution-chains/

    Post summary

    The post lists four new CVEs with associated vulnerability types and links to a lab article that outlines threat actor activity targeting BMC FootPrints.

    01042706
    6.7K followersView on X
  • bigmacd@bigmacd16684
    Active Exploitation

    🚨 Critical vulnerabilities in BMC FootPrints: Auth bypass (CVE-2025-71257), 2 SSRF bugs (CVE-2025-71258, CVE-2025-71259), Java deserialization RCE (CVE-2025-71260). Exploited by watchTowr for pre-auth R

    Post summary

    BMC FootPrints suffers critical flaws—an authentication bypass, two SSRF vulnerabilities, and a Java deserialization RCE—that have reportedly been exploited by the entity watchTowr pre-authentication.

    10000144
    3 followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2025-71258 - high 🚨 BMC FootPrints 'searchWeb' - Server-Side Request Forgery > BMC FootPrints versions 20.20.02 through 20.24.01.001 contain a Server-Side Request F... 👾 https://cloud.projectdiscovery.io/library/CVE-2025-71258 @pdnuclei #NucleiTemplates #cve

    Post summary

    The post announces the discovery of a high‑severity SSRF vulnerability (CVE‑2025‑71258) in BMC FootPrints versions 20.20.02 to 20.24.01.001, providing basic technical details but no PoC, exploit code, or patch information.

    00010242
    900 followersView on X
  • CCB Alert@CCBalert
    Disclosure

    Warning: A #pre-auth #RCE chain affecting #BMC FootPrints (ITSM) allows full compromise via chained flaws: #CVE-2025-71257, #CVE-2025-71258, #CVE-2025-71259, #CVE-2025-71260.#ITSM platforms are frequent ransomware targets. #Patch #Patch #Patch https://labs.watchtowr.com/thanks-itsms-threat-actors-have-never-been-so-organized-bmc-footprints-pre-auth-remote-code-execution-chains/

    Post summary

    The tweet announces a pre‑authentication RCE chain affecting BMC FootPrints with four CVEs, urges patching, but provides no PoC, exploit code, or evidence of active exploitation.

    00000349
    7.2K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-71258 BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind server-side request forgery vulnerability in the searchWeb API component that allows authen… https://www.cve.org/CVERecord?id=CVE-2025-71258

    Post summary

    The statement discloses CVE-2025-71258, indicating a blind SSRF flaw in BMC FootPrints ITSM’s searchWeb API, but contains no PoC, exploit, patch, or active exploitation details.

    00000114
    56.8K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2025-71258 Blind Server-Side Request Forgery in BMC FootPrints ITSM Searchable Web API https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-71258

    Post summary

    The tweet simply announces CVE‑2025‑71258 as a blind SSRF in BMC FootPrints ITSM, with no additional details on PoC, exploitation, or remediation.

    00000180
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appbmcfootprints---

Explore more