Autumn Good@autumn_good_35Active Exploitation
The post lists multiple CVEs and references an article indicating that organized threat actors are actively exploiting these flaws through pre‑auth remote code execution chains on BMC FootPrints.
pdnuclei-bot@pdnuclei_botDisclosure
A critical CVE-2025-71260 affecting BMC FootPrints Asset Core has been disclosed, indicating a pre‑authentication remote code execution vulnerability via deserialization of untrusted data. No PoC, exploit code, active exploitation, patch, or false positive claim is provided.
bigmacd@bigmacd16684Active Exploitation
The tweet announces critical vulnerabilities (auth bypass, SSRF, and Java deserialization RCE) in BMC FootPrints that are actively exploited by the threat actor watchTowr, with no PoC, exploit code, or patch information provided.
CCB Alert@CCBalertPatch
The tweet alerts about a pre-auth RCE chain against BMC FootPrints, enumerates four CVEs, and stresses the need for patching via the provided link.
CVE@CVEnewDisclosure
This excerpt announces a deserialization vulnerability (CVE‑2025‑71260) affecting specific BMC FootPrints ITSM versions, with no evidence of exploitation, patches, or PoC.
RedPacket Security@RedPacketSecGeneral
A brief CVE alert with a link, but no additional technical, exploit, or remediation details are provided.
The Hacker Wire@TheHackerWireDisclosure
The article announces a high‑severity deserialization vulnerability (CVE‑2025‑71260) in specific BMC FootPrints ITSM versions, providing technical details but no evidence of exploitation, PoC, or patch.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
The post provides a brief disclosure of CVE‑2025‑71260, describing it as an authenticated remote code execution flaw in BMC FootPrints ITSM, but lacks details on PoC, exploit tools, or patches.