CVE-2025-71259Disclosure(bmc / footprints)

HIGHCVSS 7.1 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch bmc footprints systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts

Recommended action window: Immediate (within 24h)

NVD description

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind server-side request forgery vulnerability in the externalfeed/RSS API component that allows authenticated attackers to trigger arbitrary outbound requests from the server. Attackers can exploit insufficient validation of externally supplied resource references to interact with internal services or cause resource exhaustion impacting availability. The following hotfixes remediate the vulnerability: 20.20.02, 20.20.03.002, 20.21.01.001, 20.21.02.002, 20.22.01, 20.22.01.001, 20.23.01, 20.23.01.002, and 20.24.01.

6.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • footprints

Threat summary

  • Active exploitation appears in 2 classified signals
  • Exploit tooling references are present in monitored signal
  • Patch or workaround signal is available
  • 7 mentions across 5 observed days

What's happening

  • Active exploitation reported across 2 signals
  • Exploit tool or code specified in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 4 classified signals
  • Peaked 4d ago at 2 mentions (2026-03-18); latest day: 1
  • 7 total mentions across 5 days

Affected systems

Vendors
Products
footprints

Deep dive

Activity timeline7 mentions / 5d
01122Mentions · 2026-03-18: 2Mentions · 2026-03-19: 1Mentions · 2026-03-20: 1Mentions · 2026-03-23: 2Mentions · 2026-03-24: 1Exploit Tool / Code · 2026-03-23: 1Active Exploitation · 2026-03-18: 1Active Exploitation · 2026-03-23: 1Patch / Workaround · 2026-03-24: 1Technical Details · 2026-03-18: 1Technical Details · 2026-03-19: 1Technical Details · 2026-03-20: 1Technical Details · 2026-03-23: 2Technical Details · 2026-03-24: 103-1803-1903-2003-2303-24
Signal classification3 categories
Disclosure
457.1%
Active Exploitation
228.6%
Patch
114.3%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-182
Active Exploitation1Disclosure1
2026-03-191
Disclosure1
2026-03-201
Disclosure1
2026-03-232
Active Exploitation1Disclosure1
2026-03-241
Patch1
Full discourse7 posts
  • ET Labs@ET_Labs
    Disclosure

    19 new OPEN, 30 new PRO (19 + 11) BMC FootPrints (CVE-2025-71257, CVE-2025-71258, CVE-2025-71259, CVE-2025-21760), LandUpdate808, Lumma Stealer, Proxy Service Domains, SolarWinds (CVE-2025-40554), UNK_VaporVibes, XWorm, ZPHP https://community.emergingthreats.net/t/ruleset-update-summary-2026-03-18-v11151/3236

    Post summary

    The post announces a set of newly identified CVEs across various products as part of a ruleset update, providing no additional technical or exploit information.

    03032416
    5.7K followersView on X
  • Autumn Good@autumn_good_35
    Active Exploitation

    🚨🚨🚨 CVE-2025-71257 - Authentication Bypass CVE-2025-71258 - SSRF CVE-2025-71259 - SSRF CVE-2025-71260 - Deserialization of Untrusted Data (RCE) The Most Organized Threat Actors Use Your ITSM (BMC FootPrints Pre-Auth Remote Code Execution Chains) https://labs.watchtowr.com/thanks-itsms-threat-actors-have-never-been-so-organized-bmc-footprints-pre-auth-remote-code-execution-chains/

    Post summary

    The post enumerates CVEs and indicates that threat actors are actively exploiting them via pre-auth remote code execution chains on BMC FootPrints, though no PoC, patch, or exploit code is shared.

    01042706
    6.7K followersView on X
  • bigmacd@bigmacd16684
    Active Exploitation

    🚨 Critical vulnerabilities in BMC FootPrints: Auth bypass (CVE-2025-71257), 2 SSRF bugs (CVE-2025-71258, CVE-2025-71259), Java deserialization RCE (CVE-2025-71260). Exploited by watchTowr for pre-auth R

    Post summary

    The text announces critical vulnerabilities in BMC FootPrints and confirms they are being exploited in the wild by watchTowr with pre-auth capabilities.

    10000144
    3 followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2025-71259 - high 🚨 BMC FootPrints 'feedUrl' - Server-Side Request Forgery > BMC FootPrints versions 20.20.02 through 20.24.01.001 contain a Server-Side Request F... 👾 https://cloud.projectdiscovery.io/library/CVE-2025-71259 @pdnuclei #NucleiTemplates #cve

    Post summary

    The tweet announces the discovery of a high‑severity SSRF vulnerability (CVE-2025-71259) in BMC FootPrints, but does not provide a PoC, exploit, patch, or evidence of active exploitation.

    00010207
    900 followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: A #pre-auth #RCE chain affecting #BMC FootPrints (ITSM) allows full compromise via chained flaws: #CVE-2025-71257, #CVE-2025-71258, #CVE-2025-71259, #CVE-2025-71260.#ITSM platforms are frequent ransomware targets. #Patch #Patch #Patch https://labs.watchtowr.com/thanks-itsms-threat-actors-have-never-been-so-organized-bmc-footprints-pre-auth-remote-code-execution-chains/

    Post summary

    The post discloses a chain of four pre‑authentication RCE vulnerabilities in BMC FootPrints and urges users to apply patches, with a link highlighting threat actor activity.

    00000349
    7.2K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-71259 BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind server-side request forgery vulnerability in the externalfeed/RSS API component that allows… https://www.cve.org/CVERecord?id=CVE-2025-71259

    Post summary

    The passage discloses a blind SSRF vulnerability (CVE‑2025‑71259) affecting BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 within the externalfeed/RSS API component, with no PoC, exploitation, or patch information provided.

    00000113
    56.8K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-71259 Blind Server-Side Request Forgery in BMC FootPrints ITSM 20.20.02-20.24.01.001 https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-71259

    Post summary

    This entry announces the discovery of a blind SSRF vulnerability (CVE‑2025‑71259) affecting specific versions of BMC FootPrints ITSM, without providing PoC or exploit details.

    00000179
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appbmcfootprints---

Explore more