-Infinity
0

How We Hacked Thousands of Data Centers in Minutes Using a 20-Year-Old Vulnerability

First published (updated )
Social
reddit

BMC Control-M ServerImproper deserialization handling in Control-M Components

Risk 70
Severity
8.9
First published (updated )

BMC Control-M/ServerUnauthenticated command injection in Control-M/Server communication command

Risk 80
Severity
9.5
First published (updated )

BMC Control-M/Enterprise ManagerWeak password hash protection in Control-M/Entreprise Manager

Risk 29
Severity
5.6
First published (updated )

BMC Control-M/MFTAn issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. An API management endpoint allow…

Risk 43
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

BMC Control-M/MFTSQL Injection, Input Validation

Risk 79
Severity
8.8
First published (updated )

BMC Control-M/MFTAn issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. A set of default debug user cred…

Risk 86
Severity
9.8
First published (updated )

BMC FootPrints ITSMBMC FootPrints ITSM 20.20.02 <= 20.24.01.001 VIEWSTATE Deserialization RCE

Risk 79
Severity
8.7
First published (updated )

BMC FootPrints ITSMBMC FootPrints ITSM 20.20.02 <= 20.24.01.001 Blind SSRF in externalfeed/RSS

Risk 48
Severity
5.3
First published (updated )

BMC FootPrints ITSMBMC FootPrints ITSM 20.20.02 <= 20.24.01.001 Blind SSRF in searchWeb

Risk 48
Severity
5.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

BMC FootPrints ITSMBMC FootPrints ITSM 20.20.02 <= 20.24.01.001 Authentication Bypass

Risk 66
Severity
6.9
First published (updated )

BMC Control-M/AgentBMC Control-M/Agent default configuration does not enforce SSL/TLS allowing unauthorized actions and remote code execution

Risk 87
Severity
10
First published (updated )

BMC Control-M/AgentBMC Control-M/Agent memory corruption in SSL/TLS communication

Risk 73
Severity
8.9
First published (updated )

BMC Control-M/AgentBMC Control-M/Agent buffer overflow in SSL/TLS communication

Risk 29
Severity
6.3
First published (updated )

BMC Control-M/AgentBMC Control-M/Agent buffer overflow local privilege escalation

Risk 76
Severity
9.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

BMC Control-M/AgentBMC Control-M/Agent path traversal local privilege escalation

Risk 76
Severity
9.3
First published (updated )

BMC Control-M/AgentBMC Control-M/Agent improper IP address filtering order

Risk 33
Severity
6.9
First published (updated )

BMC Control-M/AgentBMC Control-M/Agent unescaped NULL byte in access control list checks

Risk 87
Severity
10
First published (updated )

BMC Control-M/AgentBMC Control-M/Agent hardcoded Blowfish keys

Risk 55
Severity
7.6
First published (updated )

BMC Control-M/AgentBMC Control-M/Agent insecure default file permissions

Risk 32
Severity
5.7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

BMC Control-M/AgentBMC Control-M/Agent hardcoded default keystore password

Risk 32
Severity
5.7
First published (updated )

BMC Control-M/AgentBMC Control-M/Agent default SSL/TLS configuration authenticated bypass

Risk 76
Severity
9.5
First published (updated )

BMC Control-M/ServerBMC Control-M/Server cleartext database credentials in process lists and logs

Risk 23
Severity
7.8
First published (updated )

BMC Software Remedy Mid TierAn issue was discovered in BMC Remedy Mid Tier 7.6.04. The web application allows stored HTML Inject…

Risk 29
Severity
4.2
First published (updated )

BMC FirmwareImproper access control in BMC Firmware for the Intel(R) Server Board S2600WF, Intel(R) Server Board…

Risk 47
Severity
7.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

BMC Remedy Mid Tier**UNSUPPORTED WHEN ASSIGNED** An issue was discovered in BMC Remedy Mid Tier 7.6.04. An unauthentica…

Risk 86
Severity
9.8
First published (updated )

BMC Track-it\!BMC Track-It! Unrestricted File Upload Remote Code Execution Vulnerability

Risk 81
Severity
8.8
First published (updated )

BMC Track-it\!BMC Track-It! GetData Missing Authorization Information Disclosure Vulnerability

Risk 39
Severity
6.5
First published (updated )

BMC Control-MHTML injection in BMC Control-M

Risk 34
Severity
5.4
First published (updated )

BMC Control-MDLL side-loading in BMC Control-M

Risk 68
Severity
7.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203