Security1 distinct publisher3 min readUpdated
CVE-2026-27875 lets a low-privileged local user pull credentials and auth tokens out of Simplex Incident Manager memory. CISA's advisory names both v2.01.01 and v1.01.05 as the upgrade.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
CISA published an advisory on 20 August 2026 covering CVE-2026-27875 in Johnson Controls Simplex Incident Manager, which stores user credentials such as passwords and authentication tokens in unencrypted form in system memory while the application runs [1][2][3]. The consequence is not a crash or a denial of service: a local attacker with low privileges can extract those credentials and use them for unauthorized access to the application and to connected systems [4].
That last phrase is the whole story. Credentials scraped out of a console's working memory are not scoped to that console. They are the operator's identity, and they travel wherever that identity is accepted. The advisory places the affected product in the context of building automation systems, and Johnson Controls repeats CISA's general guidance to minimize risk across all of them [5]. It lists affected sectors as critical manufacturing, commercial facilities, government services and facilities, transportation systems, and energy, with deployment worldwide and the vendor headquartered in Ireland [6][7].
Affected versions are Simplex Incident Manager V2.01 and earlier [2]. The classification is CWE-316, cleartext storage of sensitive information in memory [3]. Johnson Controls reported the vulnerability to CISA itself, and CISA says no public exploitation specifically targeting it has been reported to the agency [8][9]. The advisory also states the flaw is not remotely exploitable and has high attack complexity [10]. Read that as a scoping note rather than an excuse to defer: high complexity plus local-only access describes the insider and the contractor with a laptop on the host, and the advisory explicitly names insiders with elevated privileges and memory-dumping tools as the exposure path [3].
Then there is the patch line. The remediation section says Johnson Controls has released a patched version, v2.01.01 [11], and in the next breath suggests upgrading to version v1.01.05 or later [12]. Those cannot both be right for a product whose affected ceiling is V2.01: v1.01.05 is below the range described as vulnerable [13]. Anyone building a change ticket off the mitigation bullet alone will install a version that the same document treats as affected. Johnson Controls points to its own product security advisory, JCI-PSA-2026-28, for detailed mitigation instructions, which is where the authoritative version number should be confirmed before the maintenance window is booked [14].
The compensating controls in the advisory are the usual local-access hygiene: restrict local access to authorized personnel, deploy endpoint protection and monitoring to detect memory-dumping tools or suspicious processes, enforce least privilege on hosts, use full-disk encryption and secure boot to reduce the risk of offline memory analysis, and turn on audit logging for unauthorized local access attempts [15]. Note what is not on that list: credential rotation. If the memory has been readable on a shared console for the life of every version up to V2.01, patching stops the leak but does not invalidate what already leaked.
What to watch: confirm the correct target build against JCI-PSA-2026-28 rather than the CISA bullet [14][12]; inventory who holds interactive local sessions on these hosts; and rotate any credential or token that the console has held in memory, especially service accounts that reach other building systems. The advisory as published shows no CVSS metrics under its Metrics heading, so severity ranking will have to come from your own exposure, not from the document [16].
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
CISA's ICS advisory on Johnson Controls Simplex Incident Manager has an initial release date of 2026-08-20.
Affected versions are Johnson Controls Simplex Incident Manager V2.01 and earlier, tracked as CVE-2026-27875.
The Simplex Incident Manager application stores user credentials such as passwords and authentication tokens in unencrypted form within system memory while running, exposing them to extraction by anyone with local access, including attackers using memory-dumping tools or insiders with elevated privileges. The relevant CWE is CWE-316, Cleartext Storage of Sensitive Information in Memory.
Successful exploitation could allow a local attacker with low privileges to extract user credentials (passwords and authentication tokens) from system memory, potentially leading to unauthorized access to the application and connected systems.
Aligning with CISA recommendations, Johnson Controls recommends taking steps to minimize risks to all building automation systems.
Critical infrastructure sectors listed in the advisory are Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Transportation Systems, and Energy.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Authoritative primary advisory, single source, no severity metrics
Every claim rests on a first-party CISA ICS advisory, which is the canonical record for the vulnerability, affected versions, impact and remediation, so provenance is strong. It is nonetheless a single document with no independent corroboration, no CVSS scores under its Metrics heading, and an internal contradiction in the upgrade instruction that no supplied source resolves.
No uptake data supplied
The advisory establishes that a patch exists and that the product is deployed worldwide across five sectors, but supplies no installed-base counts, patch-application rates, exposure scans, or incident telemetry. There is no basis to score real-world adoption of either the vulnerable versions or the v2.01.01 fix without inferring figures the source does not contain.
Slightly understated by the source's own remediation text
The advisory language is restrained and matches its evidence: local access required, high attack complexity, no remote exploitation, no known public exploitation. If anything the published document undersells the operational problem, because the Metrics heading is empty and the defensive-measures list names v1.01.05 as the upgrade target, a version below the affected ceiling, which understates what an operator must actually do to be patched.
Vendor self-report shapes both the risk framing and the fix text
Johnson Controls reported the vulnerability to CISA and authored the remediation and mitigation language, giving the disclosing party an interest in emphasizing the local-only, high-complexity nature of the flaw and in routing detail to its own product security advisory. CISA has a countervailing public-defense mandate and no commercial stake, which limits distortion; the self-reporting pattern itself is a cooperative-disclosure signal rather than a promotional one.
High source authority, single-source and internally inconsistent
Confidence is solid on the core facts because they come from the authoritative advisory of record and are internally specific about CVE, version ceiling, weakness class and patched build. It is held below high because the cluster has one publisher, no CVSS metrics were published, the remediation block contradicts itself on the upgrade target, and no adoption or exploitation telemetry exists to test the risk framing.
security
Siemens patches a CAE overflow that lands in the sectors that patch workstations last1 distinct publisher
build
A UDP packet is now enough: IKEEXT RCE moves from patch queue to fire drill1 distinct publisher
security
The ransom is for silence now, and your restore drill does not price that1 distinct publisher
build
GitLab bundles a zero-click GraphQL flaw with a CSRF bug, and only one needs a victim1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 20, 2026