type: cve ยท created: 2026-08-21 ยท updated: 2026-08-21 ยท tags: [cve, ics, credential-leak, johnson-controls, fire-alarm, cisa, memory-exposure] ยท confidence: high ยท severity: medium ยท affected_sectors: [construction, energy, government, transport] ยท au_impact: false
CVE-2026-27875 โ Johnson Controls Simplex Incident Manager Credential Leak
CVE-2026-27875 is a credential-exposure vulnerability (CVSS 5.8) in the Johnson Controls Simplex Gap tool, a fire-alarm and incident-management system used in commercial facilities, government, transport and energy settings. CISA published it via ICS advisory ICSA-26-232-01.
Details
| Field | Value |
|---|---|
| CVE | CVE-2026-27875 |
| CVSS | 5.8 (Medium) |
| Product | Johnson Controls Simplex Incident Manager (versions โค V2.01) |
| Type | Credential leak from system memory |
| Access | Local, low-privilege user |
| CISA advisory | ICSA-26-232-01 |
| Impact | Extracts user credentials (passwords, authentication tokens), potentially reaching the application and connected systems |
Impact
For building operators, the advisory is a reminder that building-automation and life-safety networks hold credentials with inherently privileged access to physical environments. Although the exposure requires local low-privilege access, leaked credentials can be reused to move into connected systems.
Related
- Incident page: CISA Advisory โ Johnson Controls Simplex Incident Manager Credential Leak (same entity day, incidents/)
Source
- CISA โ ICS Advisory ICSA-26-232-01 โ 2026-08-20