Researchers disclosed multiple BMC FootPrints ITSM vulnerabilities that can be chained to achieve pre-authenticated remote code execution, highlighting the product as a high-value target because ITSM platforms often contain asset inventories, incident data, configuration details, and other operationally sensitive information. watchTowr Labs said it found and chained flaws in 2025 against what was then a fully patched deployment, while broader reporting noted a set of four issues affecting the platform and framed the exposure as part of a wider pattern of attackers abusing enterprise management software.
A related disclosure, CVE-2025-71260, affects BMC FootPrints versions 20.20.02 through 20.24.01.001 and stems from unsafe ASP.NET VIEWSTATE deserialization, allowing an authenticated attacker to execute arbitrary code and fully compromise the application. The vendor has issued hotfixes for affected releases, but the references do not all describe the exact same exploit chain: the watchTowr research focuses on pre-auth RCE chains, while the CVE entry covers a specific authenticated deserialization bug, making it adjacent but not fully the same incident thread.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
The Hacker News included the BMC FootPrints pre-authentication RCE chain in its ThreatsDay bulletin as one of several significant security developments. The item was presented as part of a broader roundup rather than a new disclosure.
watchTowr Labs published technical details showing how attackers could obtain a guest-issued SEC_TOKEN, access protected functionality, abuse unsafe Java deserialization in __VIEWSTATE, and write a JSP web shell for pre-authenticated RCE. The disclosure established that fully patched FootPrints deployments were exploitable before the hotfixes.
After the issues were reported, BMC reproduced the exploit chain and issued hotfixes to address the vulnerabilities in affected FootPrints versions. CVEs CVE-2025-71257 through CVE-2025-71260 were assigned to the four flaws.
watchTowr Labs identified four vulnerabilities in BMC FootPrints that could be chained by an unauthenticated attacker to achieve remote code execution on fully patched systems at the time of discovery. The issues affected versions 20.20.02 through 20.24.01.001 and included an authentication bypass, two blind SSRF flaws, and a deserialization bug.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourcelabs.watchtowr.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.