CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

The Most Organized Threat Actors Use Your ITSM (BMC FootPrints Pre-Auth Remote Code Execution Chains)

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 563

As cited

Copy frozen at (site build).

vulnerabilities

The Most Organized Threat Actors Use Your ITSM (BMC FootPrints Pre-Auth Remote Code Execution Chains)

watchTowr Labs discovered four chained vulnerabilities in BMC FootPrints ITSM solution, including authentication bypass, server-side request forgery, and deserialization flaws that enable pre-authenticated remote code execution. The vulnerabilities affect BMC FootPrints versions 20.20.02 through 20.24.01.001, and disclosure to BMC began in June 2025. ITSM solutions like FootPrints are high-value targets because they manage IT inventory, configuration data, and incident information that organized threat actors leverage for ransomware campaigns.

Why it matters: Organizations running BMC FootPrints should immediately assess their deployment versions and apply patches when available, as ITSM solutions are frequently targeted by ransomware operators for lateral movement and reconnaissance due to their access to sensitive infrastructure data.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

The Most Organized Threat Actors Use Your ITSM (BMC FootPrints Pre-Auth Remote Code Execution Chains)

watchTowr Labs discovered four chained vulnerabilities in BMC FootPrints ITSM solution, including authentication bypass, server-side request forgery, and deserialization flaws that enable pre-authenticated remote code execution. The vulnerabilities affect BMC FootPrints versions 20.20.02 through 20.24.01.001, and disclosure to BMC began in June 2025. ITSM solutions like FootPrints are high-value targets because they manage IT inventory, configuration data, and incident information that organized threat actors leverage for ransomware campaigns.

Why it matters: Organizations running BMC FootPrints should immediately assess their deployment versions and apply patches when available, as ITSM solutions are frequently targeted by ransomware operators for lateral movement and reconnaissance due to their access to sensitive infrastructure data.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary