Blog/vulnerabilities
vulnerabilities

Johnson Controls Simplex Incident Manager

August 20, 2026·Source: CISA
0 comments

TL;DR

View CSAF Summary Successful exploitation of this vulnerability could allow a local attacker with low privileges to extract user credentials (passwords and authentication tokens) from system memory, potentially leading to unauthorized access to the application and connected systems. The following versions of Johnson Controls Simplex Incident Manager are affected: Simplex Incident Manager <=V2.01 (CVE-2026-27875) CVSS Vendor Equipment Vulnerabilities

v3 5.8 Johnson Controls Inc. Johnson Controls Simplex Incident Manager Cleartext Storage of Sensitive Information in Memory

Background Critical Infrastructure Sectors: Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Transportation Systems, Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Ireland Vulnerabilities Expand All + CVE-2026-27875 The Simplex Incident Manager application stores user credentials (such as passwords and authentication tokens) in an unencrypted form within system memory while running. This exposes sensitive information to potential extraction by anyone with local access to the system, including attackers leveraging memory-dumping tools or insiders with elevated privileges. View CVE Details Affected Products Johnson Controls Simplex Incident Manager Vendor: Johnson Controls Inc. Product Version: Johnson Controls Simplex Incident Manager: <=V2.01 Product Status: known_affected Remediations Mitigation Johnson Controls has released a patched version (v2.01.01) to address this vulnerability. To help reduce the risk of exploitation, Johnson Controls suggests considering the following defensive measures: Upgrade the Simplex Incident Manager to version v1.01.05 or later. Restrict local access to systems running the Simplex Incident Manager to authorized personnel only. Implement endpoint protection and monitoring to detect memory-dumping tools or suspicious processes. Enforce strong access control policies and the principle of least privileg

What Happened

Johnson Controls Simplex Incident Manager, reported by CISA.

View CSAF Summary Successful exploitation of this vulnerability could allow a local attacker with low privileges to extract user credentials (passwords and authentication tokens) from system memory, potentially leading to unauthorized access to the application and connected systems. The following versions of Johnson Controls Simplex Incident Manager are affected: Simplex Incident Manager <=V2.01 (CVE-2026-27875) CVSS Vendor Equipment Vulnerabilities

v3 5.8 Johnson Controls Inc. Johnson Controls Simplex Incident Manager Cleartext Storage of Sensitive Information in Memory

Background Critical Infrastructure Sectors: Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Transportation Systems, Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Ireland Vulnerabilities Expand All + CVE-2026-27875 The Simplex Incident Manager application stores user credentials (such as passwords and authentication tokens) in an unencrypted form within system memory while running. This exposes sensitive information to potential extraction by anyone with local access to the system, including attackers leveraging memory-dumping tools or insiders with elevated privileges. View CVE Details Affected Products Johnson Controls Simplex Incident Manager Vendor: Johnson Controls Inc. Product Version: Johnson Controls Simplex Incident Manager: <=V2.01 Product Status: known_affected Remediations Mitigation Johnson Controls has released a patched version (v2.01.01) to address this vulnerability. To help reduce the risk of exploitation, Johnson Controls suggests considering the following defensive measures: Upgrade the Simplex Incident Manager to version v1.01.05 or later. Restrict local access to systems running the Simplex Incident Manager to authorized personnel only. Implement endpoint protection and monitoring to detect memory-dumping tools or suspicious processes. Enforce strong access control policies and the principle of least privileg

For the full technical details, see the original report.

Why It Matters for Businesses

This development could affect organizations that rely on the impacted technologies or services. Unpatched systems, misconfigured infrastructure, or lack of monitoring can leave businesses exposed to exploitation, data breaches, and regulatory penalties.

How to Check Your Exposure

Run a free scan on NEL Professional's Cyber Risk Scanner to check whether your domain is affected. The scan covers SSL/TLS, security headers, DNS configuration, email authentication, and more across 16 modules.

Check Your Domain Security

Mitigation Steps

  • Patch immediately, Apply vendor patches or updates as soon as they are available.
  • Review configurations, Check firewall rules, access controls, and security headers.
  • Monitor logs, Watch for indicators of compromise (IOCs) related to this threat.
  • Update security policies, Ensure incident response plans cover this type of threat.
  • Run a security scan, Use automated tools to verify your exposure.

Need Expert Help?

If your organization needs help assessing or remediating this issue, hire a verified cybersecurity specialist through NEL Professionals.

Need More Scan Credits?

Get up to 100 scans or unlimited lifetime access starting at $15.

View Plans →

Comments (0)

No comments yet. Be the first to comment!

← Back to Blog