CVE-2026-27875
View CSAF Summary Successful exploitation of this vulnerability could allow a local attacker with low privileges to extract user credentials (passwords and authentication tokens) from system memory, potentially leading to unauthorized access to the application and connected systems. The following versions of Johnson Controls Simplex Incident Manager are affected: Simplex Incident Manager <=V2.01 (CVE-2026-27875) CVSS Vendor Equipment Vulnerabilities v3 5.8 Johnson Controls Inc. Johnson Controls Simplex Incident Manager Cleartext Storage of Sensitive Information in Memory Background Critical Infrastructure Sectors: Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Transportation Systems, Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Ireland Vulnerabilities Expand All + CVE-2026-27875 The Simplex Incident Manager application stores user credentials (such as passwords and authentication tokens) in an unencrypted form within system memory while running. This exposes sensitive information to potential extraction by anyone with local access to the system, including attackers leveraging memory-dumping tools or insiders with elevated privileges. View CVE Details Affected Products Johnson Controls Simplex Incident Manager Vendor: Johnson Controls Inc. Product Version: Johnson Controls Simplex Incident Manager: <=V2.01 Product Status: known_affected Remediations Mitigation Johnson Controls has released a patched version (v2.01.01) to address this vulnerability. To help reduce the risk of exploitation, Johnson Controls suggests considering the following defensive measures: Upgrade the Simplex Incident Manager to version v1.01.05 or later. Restrict local access to systems running the Simplex Incident Manager to authorized personnel only. Implement endpoint protection and monitoring to detect memory-dumping tools or suspicious processes. Enforce strong access control policies and the principle of least privilege on hos
CSIRTS triage
- What
- The application stores sensitive information including passwords and authentication tokens in cleartext in system memory.
- Who is affected
- Deployments of Simplex Incident Manager version 2.01 and earlier are affected; exploitation requires local access with low privileges.
- Urgency
- Immediate patching is required; credentials can be extracted from memory allowing unauthorized access to the application and connected systems.
- Action
- Upgrade to a version newer than V2.01 as soon as possible.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-27875
Get an email if CVE-2026-27875 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.08% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 0% of all EPSS-scored CVEs.
Advisory coverage (3)
- high[UPDATE] [high] Grafana: Multiple vulnerabilitiescert-bund · 2026-08-24
- unknownCVE-2026-27875: Cleartext Storage of Sensitive Information in Memory vulnerability in Johnson Controls Simplex…nvd · 2026-08-21
- criticalJohnson Controls Simplex Incident Managercisa · 2026-08-20
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-27875)