BMC Software's vulnerability footprint spans enterprise systems management and IT service automation products widely deployed across large organizations, presenting a significant attack surface in critical infrastructure layers. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a corresponding tendency toward public exploit availability, reflecting the high-value target profile of IT operations software. The exposure concentrates in flagship products such as Patrol Agent and Control-M Agent, alongside the Track-It ticketing platform, and recurs through weakness classes including improper authentication, cross-site scripting, SQL injection, and insecure default permissions—vulnerabilities characteristic of web-facing and authentication-dependent enterprise tools. Defenders should prioritize patching and inventory of BMC products in networked environments, particularly those accessible from less-trusted network segments; live exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bmc over time
Signals from CVEs in this vendor scope (81 CVEs).
81 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-4872HIGH BMC Track-It! 11.3.0.355 does not require authentication on TCP port 9010, which allows remote attackers to upload arbitrary files, execute arbitrary code, or obtain sensitive cred | Oct 10, 2014 | 7.5 | 83 | NO | YES |
CVE-2016-1542HIGH The RPC API in RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and UNIX allows remote attackers to bypass authorization and enum | Jun 13, 2016 | 7.5 | 82 | NO | YES |
CVE-2016-1543HIGH The RPC API in the RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and UNIX allows remote attackers to bypass authorization and | Jun 13, 2016 | 7.5 | 81 | NO | YES |
CVE-2025-71260HIGH BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a deserialization of untrusted data vulnerability in the ASP.NET servlet's VIEWSTATE handling that allows authent | Mar 19, 2026 | 8.8 | 62 | NO | YES |
CVE-2016-6598CRITICAL BMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting file storage service (FileStorageService) on port 9010. This service contains a method that allows uploa | Jan 30, 2018 | 9.8 | 51 | NO | YES |
CVE-2025-71258HIGH BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind server-side request forgery vulnerability in the searchWeb API component that allows authenticated attack | Mar 19, 2026 | 7.1 | 49 | NO | YES |
CVE-2016-6599CRITICAL BMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting configuration service (ConfigurationService) on port 9010. This service contains a method that can be us | Jan 30, 2018 | 9.8 | 49 | NO | YES |
CVE-2018-20735HIGH An issue was discovered in BMC PATROL Agent through 11.3.01. It was found that the PatrolCli application can allow for lateral movement and escalation of privilege inside a Windows | Jan 17, 2019 | 7.8 | 47 | NO | YES |
CVE-2025-71259HIGH BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind server-side request forgery vulnerability in the externalfeed/RSS API component that allows authenticated | Mar 19, 2026 | 7.1 | 46 | NO | YES |
CVE-2025-71257CRITICAL BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain an authentication bypass vulnerability due to improper enforcement of security filters on restricted REST API end | Mar 19, 2026 | 9.1 | 45 | NO | YES |
Signals from CVEs in this vendor scope (81 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bmc.
Media articles that mention a CVE ID that affects a product developed by Bmc — matched by CVE ID, not by vendor name.