Skip to main content
CISA — industrial system·IE·

Johnson Controls Simplex Incident Manager

View CSAF Summary Successful exploitation of this vulnerability could allow a local attacker with low privileges to extract user credentials (passwords and authentication tokens) from system memory, potentially leading to unauthorized access to the application and connected systems. The following versions of Johnson Controls Simplex Incident Manager are affected: Simplex Incident Manager <=V2.01 (CVE-2026-27875) CVSS Vendor Equipment Vulnerabilities v3 5.8 Johnson Controls Inc. Johnson Controls Simplex Incident Manager Cleartext Storage of Sensitive Information in Memory Background Critical Infrastructure Sectors: Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Transportation Systems, Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Ireland Vulnerabilities Expand All + CVE-2026-27875 The Simplex Incident Manager application stores user credentials (such as passwords and authentication tokens) in an unencrypted form within system memory while running. This exposes sensitive information to potential extraction by anyone with local access to the system, including attackers leveraging memory-dumping tools or insiders with elev

More from CISA — industrial system

The rest of this wire is for subscribers

Every release from this source, the moment it crosses — plus 80+ other newswires, saved searches and instant alerts.

7 days, no card required.

Read releases like this the second they cross the wire.

1,400+ feeds — live on PPN World right now. Every release from this source, the moment it crosses — plus 80+ other newswires, saved searches and instant alerts.

Start the free trial →

Your announcement next? Distribute your press release to the global wires with PPN Source — and track its pickup live here.

PPN Source →
Shared via PPN World — real-time press release intelligence.