BMC FootPrints - Deserialization of Untrusted Data (RCE)
CVE-2025-71260
Verified
Description
BMC FootPrints Asset Core is vulnerable to pre-authentication remote code execution via Java deserialization in the aspnetconfig endpoint.
Severity
Critical
Published Date
March 19, 2026
Template Author
watchtowr, dhiyaneshdk
CVE-2025-71260.yaml
9.5Severity
CVSS Metrics
References
https://labs.watchtowr.com/thanks-itsms-threat-actors-have-never-been-so-organized-bmc-footprints-pre-auth-remote-code-execution-chains/https://github.com/watchtowrlabs/watchTowr-vs-BMC-Footprints-RCE-CVE-2025-71257-CVE-2025-71260/blob/main/watchTowr-vs-BMC-Footprints-RCE-CVE-2025-71257-CVE-2025-71260.pyhttps://nvd.nist.gov/vuln/detail/CVE-2025-71260
Remediation Steps
Upgrade BMC FootPrints to the latest patched version.