Security1 publisher3 min readPublished
Johnson Controls console holds passwords in cleartext memory, and the fix line names two versions
CVE-2026-27875 lets a low-privileged local user pull credentials and auth tokens out of Simplex Incident Manager memory. CISA's advisory names both v2.01.01 and v1.01.05 as the upgrade.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- CISA's ICS advisory on Johnson Controls Simplex Incident Manager has an initial release date of 2026-08-20.
- Affected versions are Johnson Controls Simplex Incident Manager V2.01 and earlier, tracked as CVE-2026-27875.
- The Simplex Incident Manager application stores user credentials such as passwords and authentication tokens in unencrypted form within system memory while running, exposing them to extraction by anyone with local access, including attackers using memory-dumping tools or insiders with elevated privileges. The relevant CWE is CWE-316, Cleartext Storage of Sensitive Information in Memory.
- Successful exploitation could allow a local attacker with low privileges to extract user credentials (passwords and authentication tokens) from system memory, potentially leading to unauthorized access to the application and connected systems.
- Aligning with CISA recommendations, Johnson Controls recommends taking steps to minimize risks to all building automation systems.
Compiled by The WatchSomething wrong?How this is made
Why it matters
CISA published an advisory on 20 August 2026 covering CVE-2026-27875 in Johnson Controls Simplex Incident Manager, which stores user credentials such as passwords and authentication tokens in unencrypted form in system memory while the application runs [1][2][3]. The consequence is not a crash or a denial of service: a local attacker with low privileges can extract those credentials and use them for unauthorized access to the application and to connected systems [4].
That last phrase is the whole story. Credentials scraped out of a console's working memory are not scoped to that console. They are the operator's identity, and they travel wherever that identity is accepted. The advisory places the affected product in the context of building automation systems, and Johnson Controls repeats CISA's general guidance to minimize risk across all of them [5]. It lists affected sectors as critical manufacturing, commercial facilities, government services and facilities, transportation systems, and energy, with deployment worldwide and the vendor headquartered in Ireland [6][7].
Affected versions are Simplex Incident Manager V2.01 and earlier [2]. The classification is CWE-316, cleartext storage of sensitive information in memory [3]. Johnson Controls reported the vulnerability to CISA itself, and CISA says no public exploitation specifically targeting it has been reported to the agency [8][9]. The advisory also states the flaw is not remotely exploitable and has high attack complexity [10]. Read that as a scoping note rather than an excuse to defer: high complexity plus local-only access describes the insider and the contractor with a laptop on the host, and the advisory explicitly names insiders with elevated privileges and memory-dumping tools as the exposure path [3].
Then there is the patch line. The remediation section says Johnson Controls has released a patched version, v2.01.01 [11], and in the next breath suggests upgrading to version v1.01.05 or later [12]. Those cannot both be right for a product whose affected ceiling is V2.01: v1.01.05 is below the range described as vulnerable [13]. Anyone building a change ticket off the mitigation bullet alone will install a version that the same document treats as affected. Johnson Controls points to its own product security advisory, JCI-PSA-2026-28, for detailed mitigation instructions, which is where the authoritative version number should be confirmed before the maintenance window is booked [14].
The compensating controls in the advisory are the usual local-access hygiene: restrict local access to authorized personnel, deploy endpoint protection and monitoring to detect memory-dumping tools or suspicious processes, enforce least privilege on hosts, use full-disk encryption and secure boot to reduce the risk of offline memory analysis, and turn on audit logging for unauthorized local access attempts [15]. Note what is not on that list: credential rotation. If the memory has been readable on a shared console for the life of every version up to V2.01, patching stops the leak but does not invalidate what already leaked.
What to watch: confirm the correct target build against JCI-PSA-2026-28 rather than the CISA bullet [14][12]; inventory who holds interactive local sessions on these hosts; and rotate any credential or token that the console has held in memory, especially service accounts that reach other building systems. The advisory as published shows no CVSS metrics under its Metrics heading, so severity ranking will have to come from your own exposure, not from the document [16].