CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-27875

criticalcovered by 3 sourcesfirst seen 2026-08-20
View CSAF Summary Successful exploitation of this vulnerability could allow a local attacker with low privileges to extract user credentials (passwords and authentication tokens) from system memory, potentially leading to unauthorized access to the application and connected systems. The following versions of Johnson Controls Simplex Incident Manager are affected: Simplex Incident Manager <=V2.01 (CVE-2026-27875) CVSS Vendor Equipment Vulnerabilities v3 5.8 Johnson Controls Inc. Johnson Controls Simplex Incident Manager Cleartext Storage of Sensitive Information in Memory Background Critical Infrastructure Sectors: Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Transportation Systems, Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Ireland Vulnerabilities Expand All + CVE-2026-27875 The Simplex Incident Manager application stores user credentials (such as passwords and authentication tokens) in an unencrypted form within system memory while running. This exposes sensitive information to potential extraction by anyone with local access to the system, including attackers leveraging memory-dumping tools or insiders with elevated privileges. View CVE Details Affected Products Johnson Controls Simplex Incident Manager Vendor: Johnson Controls Inc. Product Version: Johnson Controls Simplex Incident Manager: <=V2.01 Product Status: known_affected Remediations Mitigation Johnson Controls has released a patched version (v2.01.01) to address this vulnerability. To help reduce the risk of exploitation, Johnson Controls suggests considering the following defensive measures: Upgrade the Simplex Incident Manager to version v1.01.05 or later. Restrict local access to systems running the Simplex Incident Manager to authorized personnel only. Implement endpoint protection and monitoring to detect memory-dumping tools or suspicious processes. Enforce strong access control policies and the principle of least privilege on hos

CSIRTS triage

What
The application stores sensitive information including passwords and authentication tokens in cleartext in system memory.
Who is affected
Deployments of Simplex Incident Manager version 2.01 and earlier are affected; exploitation requires local access with low privileges.
Urgency
Immediate patching is required; credentials can be extracted from memory allowing unauthorized access to the application and connected systems.
Action
Upgrade to a version newer than V2.01 as soon as possible.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-27875

Get an email if CVE-2026-27875 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (3)

External references

NVD record for CVE-2026-27875

CVE.org record

Embed the live status

CVE-2026-27875 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-27875 status](https://www.csirts.com/badge/CVE-2026-27875)](https://www.csirts.com/cve/CVE-2026-27875)