Home ยท Wiki ยท Vulnerabilities & CVEs
type: cve ยท created: 2026-08-21 ยท updated: 2026-08-21 ยท tags: [cve, ics, credential-leak, johnson-controls, fire-alarm, cisa, memory-exposure] ยท confidence: high ยท severity: medium ยท affected_sectors: [construction, energy, government, transport] ยท au_impact: false

CVE-2026-27875 โ€” Johnson Controls Simplex Incident Manager Credential Leak

CVE-2026-27875 is a credential-exposure vulnerability (CVSS 5.8) in the Johnson Controls Simplex Gap tool, a fire-alarm and incident-management system used in commercial facilities, government, transport and energy settings. CISA published it via ICS advisory ICSA-26-232-01.

Details

Field Value
CVE CVE-2026-27875
CVSS 5.8 (Medium)
Product Johnson Controls Simplex Incident Manager (versions โ‰ค V2.01)
Type Credential leak from system memory
Access Local, low-privilege user
CISA advisory ICSA-26-232-01
Impact Extracts user credentials (passwords, authentication tokens), potentially reaching the application and connected systems

Impact

For building operators, the advisory is a reminder that building-automation and life-safety networks hold credentials with inherently privileged access to physical environments. Although the exposure requires local low-privilege access, leaked credentials can be reused to move into connected systems.

Related

  • Incident page: CISA Advisory โ€” Johnson Controls Simplex Incident Manager Credential Leak (same entity day, incidents/)

Source