LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2025-71260

CVE-2025-71260 - Vulnerability Analysis

HighCVSS: 8.8

Last Updated: March 19, 2026

BMC FootPrints ITSM - Remote Code Execution

Published: March 19, 2026Updated: March 19, 2026Remote Exploitable

Overview

BMC FootPrints ITSM 20.20.02 through 20.24.01.001 contains an insecure deserialization vulnerability in ASP.NET servlet VIEWSTATE handling, letting authenticated attackers execute arbitrary code remotely, exploit requires authentication.

Severity & Score

Severity: High
CVSS Score: 8.8
EPSS Score: 0.0%(Probability of exploitation in next 30 days)

Impact

Authenticated attackers can execute arbitrary code remotely, fully compromising the application.

Mitigation

Apply hotfixes 20.20.02, 20.20.03.002, 20.21.01.001, 20.21.02.002, 20.22.01, 20.22.01.001, 20.23.01, 20.23.01.002, or 20.24.01.

Social Media Activity(2 posts)

TheHackerWire
TheHackerWire
@thehackerwire
Mar 19, 2026

🟠 CVE-2025-71260 - High (8.8) BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a deserialization of untrusted data vulnerability in the ASP.NET servlet's VIEWSTATE handling that allows authenticated attackers to execute arbitrary code. Attackers can supply cr... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2025-71260/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post
TheHackerWire
TheHackerWire
@thehackerwire
Mar 19, 2026

🟠 CVE-2025-71260 - High (8.8) BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a deserialization of untrusted data vulnerability in the ASP.NET servlet's VIEWSTATE handling that allows authenticated attackers to execute arbitrary code. Attackers can supply cr... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2025-71260/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2025-71260
Severity
High
CVSS Score
8.8
Type
insecure_deserialization
Status
new
EPSS
0.0%
Social Posts
2

CWE

  • CWE-502

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Score

0.0%Probability of exploitation in the next 30 days