type: incident ยท created: 2026-08-21 ยท updated: 2026-08-21 ยท tags: [incident, advisory, ics, credential-leak, fire-alarm] ยท confidence: high ยท affected_sectors: [construction, energy, transport, government] ยท au_impact: false
CISA Advisory: Johnson Controls Simplex Incident Manager Credential Leak
CISA published ICS advisory ICSA-26-232-01 for the Johnson Controls Simplex Incident Manager (versions <= V2.01) covering fire-alarm and incident-management systems in commercial facilities, government, transport and energy settings.
Key Facts
| Field | Detail |
|---|---|
| CVE | CVE-2026-27875 |
| CVSS | 5.8 rating |
| Product | Johnson Controls Simplex Incident Manager (<= V2.01) |
| Type | Credential leak from system memory |
| Access | Local low-privilege attacker |
| Exposed | User credentials โ passwords and authentication tokens โ potentially reaching the application and connected systems |
Successful exploitation lets a local low-privilege attacker extract user credentials from system memory, potentially reaching the application and connected systems. For building operators, the advisory is a reminder that building-automation and life-safety networks hold credentials with inherently privileged access to physical environments.
Source
- CISA โ ICS Advisory ICSA-26-232-01 โ 2026-08-20