Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-08-21 ยท updated: 2026-08-21 ยท tags: [incident, advisory, ics, credential-leak, fire-alarm] ยท confidence: high ยท affected_sectors: [construction, energy, transport, government] ยท au_impact: false

CISA Advisory: Johnson Controls Simplex Incident Manager Credential Leak

CISA published ICS advisory ICSA-26-232-01 for the Johnson Controls Simplex Incident Manager (versions <= V2.01) covering fire-alarm and incident-management systems in commercial facilities, government, transport and energy settings.

Key Facts

Field Detail
CVE CVE-2026-27875
CVSS 5.8 rating
Product Johnson Controls Simplex Incident Manager (<= V2.01)
Type Credential leak from system memory
Access Local low-privilege attacker
Exposed User credentials โ€” passwords and authentication tokens โ€” potentially reaching the application and connected systems

Successful exploitation lets a local low-privilege attacker extract user credentials from system memory, potentially reaching the application and connected systems. For building operators, the advisory is a reminder that building-automation and life-safety networks hold credentials with inherently privileged access to physical environments.

Source