Johnson Controls Simplex Incident Manager
ID: ab1e1576-b966-5905-820d-82496c8fd7f1
STIX ID: report--ab1e1576-b966-5905-820d-82496c8fd7f1
Feed Name: CISA Advisories
Threat Score
CISA reports a vulnerability (CVE-2026-27875) in Johnson Controls Simplex Incident Manager (<=V2.01) where user credentials and authentication tokens are stored unencrypted in system memory, allowing local attackers or insiders with memory-dump capability to extract sensitive information; the flaw is not remotely exploitable, has high attack complexity, no known public exploitation, and affects systems deployed in multiple critical infrastructure sectors worldwide.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
