CVE-2025-71260Disclosure(bmc / footprints)

MEDIUMCVSS 8.7 · HIGH

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch bmc footprints systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a deserialization of untrusted data vulnerability in the ASP.NET servlet's VIEWSTATE handling that allows authenticated attackers to execute arbitrary code. Attackers can supply crafted serialized objects to the VIEWSTATE parameter to achieve remote code execution and fully compromise the application. The following hotfixes remediate the vulnerability: 20.20.02, 20.20.03.002, 20.21.01.001, 20.21.02.002, 20.22.01, 20.22.01.001, 20.23.01, 20.23.01.002, and 20.24.01.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • footprints

Threat summary

  • Active exploitation appears in 2 classified signals
  • Patch or workaround signal is available
  • 9 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 8 signals
  • Disclosure: 4 classified signals
  • Peaked 4d ago at 3 mentions (2026-03-19); latest day: 1
  • 9 total mentions across 6 days

Affected systems

Vendors
Products
footprints

Deep dive

Activity timeline9 mentions / 6d
01223Mentions · 2026-03-18: 1Mentions · 2026-03-19: 3Mentions · 2026-03-20: 1Mentions · 2026-03-23: 2Mentions · 2026-03-24: 1Mentions · 2026-03-25: 1Active Exploitation · 2026-03-18: 1Active Exploitation · 2026-03-23: 1Patch / Workaround · 2026-03-19: 1Patch / Workaround · 2026-03-24: 1Technical Details · 2026-03-18: 1Technical Details · 2026-03-19: 3Technical Details · 2026-03-23: 2Technical Details · 2026-03-24: 1Technical Details · 2026-03-25: 103-1803-1903-2003-2303-2403-25
Signal classification4 categories
Disclosure
444.4%
Active Exploitation
222.2%
Patch
222.2%
General
111.1%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-03-181
Active Exploitation1
2026-03-193
Disclosure2Patch1
2026-03-201
General1
2026-03-232
Active Exploitation1Disclosure1
2026-03-241
Patch1
2026-03-251
Disclosure1
Full discourse9 posts
  • Autumn Good@autumn_good_35
    Active Exploitation

    🚨🚨🚨 CVE-2025-71257 - Authentication Bypass CVE-2025-71258 - SSRF CVE-2025-71259 - SSRF CVE-2025-71260 - Deserialization of Untrusted Data (RCE) The Most Organized Threat Actors Use Your ITSM (BMC FootPrints Pre-Auth Remote Code Execution Chains) https://labs.watchtowr.com/thanks-itsms-threat-actors-have-never-been-so-organized-bmc-footprints-pre-auth-remote-code-execution-chains/

    Post summary

    The post lists multiple CVEs and references an article indicating that organized threat actors are actively exploiting these flaws through pre‑auth remote code execution chains on BMC FootPrints.

    01042706
    6.7K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2025-71260 - critical 🚨 BMC FootPrints - Deserialization of Untrusted Data (RCE) > BMC FootPrints Asset Core is vulnerable to pre-authentication remote code execution v... 👾 https://cloud.projectdiscovery.io/library/CVE-2025-71260 @pdnuclei #NucleiTemplates #cve

    Post summary

    A critical CVE-2025-71260 affecting BMC FootPrints Asset Core has been disclosed, indicating a pre‑authentication remote code execution vulnerability via deserialization of untrusted data. No PoC, exploit code, active exploitation, patch, or false positive claim is provided.

    00011215
    904 followersView on X
  • bigmacd@bigmacd16684
    Active Exploitation

    🚨 Critical vulnerabilities in BMC FootPrints: Auth bypass (CVE-2025-71257), 2 SSRF bugs (CVE-2025-71258, CVE-2025-71259), Java deserialization RCE (CVE-2025-71260). Exploited by watchTowr for pre-auth R

    Post summary

    The tweet announces critical vulnerabilities (auth bypass, SSRF, and Java deserialization RCE) in BMC FootPrints that are actively exploited by the threat actor watchTowr, with no PoC, exploit code, or patch information provided.

    10000144
    3 followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: A #pre-auth #RCE chain affecting #BMC FootPrints (ITSM) allows full compromise via chained flaws: #CVE-2025-71257, #CVE-2025-71258, #CVE-2025-71259, #CVE-2025-71260.#ITSM platforms are frequent ransomware targets. #Patch #Patch #Patch https://labs.watchtowr.com/thanks-itsms-threat-actors-have-never-been-so-organized-bmc-footprints-pre-auth-remote-code-execution-chains/

    Post summary

    The tweet alerts about a pre-auth RCE chain against BMC FootPrints, enumerates four CVEs, and stresses the need for patching via the provided link.

    00000349
    7.2K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-71260 BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a deserialization of untrusted data vulnerability in the http://ASP.NET servlet's VIEWSTATE handling that … https://www.cve.org/CVERecord?id=CVE-2025-71260

    Post summary

    This excerpt announces a deserialization vulnerability (CVE‑2025‑71260) affecting specific BMC FootPrints ITSM versions, with no evidence of exploitation, patches, or PoC.

    00000128
    56.8K followersView on X
  • RedPacket Security@RedPacketSec
    General

    CVE Alert: CVE-2025-71260 - BMC Software, Inc. - FootPrints - https://www.redpacketsecurity.com/cve-alert-cve-2025-71260-bmc-software-inc-footprints/ #OSINT #ThreatIntel #CyberSecurity #cve-2025-71260 #bmc-software-inc #footprints

    Post summary

    A brief CVE alert with a link, but no additional technical, exploit, or remediation details are provided.

    00000245
    3.6K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2025-71260 - High BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a deserialization of untrusted data vulnerability in the http://ASP.NET servlet's VIEWSTATE handling that allows authenticated atta... https://www.thehackerwire.com/vulnerability/CVE-2025-71260/ https://t.co/1hujwXqVZK

    Post summary

    The article announces a high‑severity deserialization vulnerability (CVE‑2025‑71260) in specific BMC FootPrints ITSM versions, providing technical details but no evidence of exploitation, PoC, or patch.

    00000202
    137 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-71260 Authenticated Remote Code Execution in BMC FootPrints ITSM via De... https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-71260 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The post provides a brief disclosure of CVE‑2025‑71260, describing it as an authenticated remote code execution flaw in BMC FootPrints ITSM, but lacks details on PoC, exploit tools, or patches.

    00000193
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2025-71260: HIGH] Critical vulnerability in BMC FootPrints ITSM versions 20.20.02 to 20.24.01.001 allows attackers to execute arbitrary code. Apply hotfixes to protect against remote code execution.#cve,CVE-2025-71260,#cybersecurity https://cvefind.com/CVE-2025-71260

    Post summary

    The post announces CVE-2025-71260, a high‑severity vulnerability that enables remote code execution in certain BMC FootPrints ITSM versions, and urges customers to apply the available hotfixes.

    00000194
    603 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appbmcfootprints---

Explore more