/Vulnerability Library

BMC FootPrints - Deserialization of Untrusted Data (RCE)

CVE-2025-71260
Verified

Description

BMC FootPrints Asset Core is vulnerable to pre-authentication remote code execution via Java deserialization in the aspnetconfig endpoint.

Severity

Critical

Published Date

March 19, 2026

Template Author

watchtowr, dhiyaneshdk

CVE-2025-71260.yaml
9.5Severity

CVSS Metrics

References

https://labs.watchtowr.com/thanks-itsms-threat-actors-have-never-been-so-organized-bmc-footprints-pre-auth-remote-code-execution-chains/https://github.com/watchtowrlabs/watchTowr-vs-BMC-Footprints-RCE-CVE-2025-71257-CVE-2025-71260/blob/main/watchTowr-vs-BMC-Footprints-RCE-CVE-2025-71257-CVE-2025-71260.pyhttps://nvd.nist.gov/vuln/detail/CVE-2025-71260

Remediation Steps

Upgrade BMC FootPrints to the latest patched version.