Government Advisory

Security Flaw Found in Johnson Controls Simplex Incident Manager Could Expose User Credentials

CISA · 20 Aug 2026
Key Takeaway If your business uses Johnson Controls Simplex Incident Manager, check with your IT provider for available patches and restrict local device access until the issue is resolved.

CISA has published an advisory for a vulnerability affecting Johnson Controls Simplex Incident Manager (versions V2.01 and earlier), used across critical sectors including manufacturing, commercial facilities, government, transportation and energy worldwide.

The flaw, tracked as CVE-2026-27875, involves cleartext storage of sensitive information in memory. This means that user credentials, including passwords and authentication tokens, are stored in a readable format that a local attacker with low privileges could extract. If exploited, this could lead to unauthorized access to the Incident Manager application and any systems it connects to. The vulnerability has been rated with a CVSS v3 score of 5.8, indicating a moderate severity level.

While the attack requires local access rather than remote exploitation, organisations using this software as part of building or facility incident management systems should treat this seriously, especially if devices are shared or accessible by multiple staff or contractors. Businesses relying on Johnson Controls systems should check for vendor patches or mitigation guidance and monitor CISA advisories for updates.

Johnson Controls ICS Security Vulnerability Advisory

Summarised by CISO AI from CISA. We link back to every original so you can read it yourself.