Security Flaw Found in Johnson Controls Simplex Incident Manager Could Expose User Credentials
CISA has published an advisory for a vulnerability affecting Johnson Controls Simplex Incident Manager (versions V2.01 and earlier), used across critical sectors including manufacturing, commercial facilities, government, transportation and energy worldwide.
The flaw, tracked as CVE-2026-27875, involves cleartext storage of sensitive information in memory. This means that user credentials, including passwords and authentication tokens, are stored in a readable format that a local attacker with low privileges could extract. If exploited, this could lead to unauthorized access to the Incident Manager application and any systems it connects to. The vulnerability has been rated with a CVSS v3 score of 5.8, indicating a moderate severity level.
While the attack requires local access rather than remote exploitation, organisations using this software as part of building or facility incident management systems should treat this seriously, especially if devices are shared or accessible by multiple staff or contractors. Businesses relying on Johnson Controls systems should check for vendor patches or mitigation guidance and monitor CISA advisories for updates.