CYBERSECURITYTRACKER
TRACKING
Permanent story citation

Johnson Controls Simplex Incident Manager

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4807

As cited

Copy frozen at (site build).

vulnerabilities

Johnson Controls Simplex Incident Manager

Johnson Controls Simplex Incident Manager versions 2.01 and earlier store user credentials and authentication tokens in unencrypted system memory, allowing local attackers with low privileges to extract sensitive information using memory-dumping tools. The vulnerability (CVE-2026-27875) carries a CVSS score of 5.8 and affects critical infrastructure systems worldwide. Johnson Controls has released patched versions and recommends upgrading, restricting local access, and implementing endpoint protection and monitoring.

Why it matters: Organizations operating Simplex Incident Manager in critical manufacturing, energy, transportation, or government facilities must upgrade to v2.01.01 or later to prevent local attackers from stealing credentials that could grant unauthorized access to building automation and connected systems.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Johnson Controls Simplex Incident Manager

Johnson Controls Simplex Incident Manager versions 2.01 and earlier store user credentials and authentication tokens in unencrypted system memory, allowing local attackers with low privileges to extract sensitive information using memory-dumping tools. The vulnerability (CVE-2026-27875) carries a CVSS score of 5.8 and affects critical infrastructure systems worldwide. Johnson Controls has released patched versions and recommends upgrading, restricting local access, and implementing endpoint protection and monitoring.

Why it matters: Organizations operating Simplex Incident Manager in critical manufacturing, energy, transportation, or government facilities must upgrade to v2.01.01 or later to prevent local attackers from stealing credentials that could grant unauthorized access to building automation and connected systems.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary