Upgrade Johnson Controls Simplex Incident Manager to version v2.01.01 or later. Restrict local access to authorized personnel only. Implement endpoint protection and monitoring to detect memory-dumping tools or suspicious processes. Enforce strong access control policies and the principle of least privilege on host systems. Utilize full-disk encryption and secure boot to reduce the risk of offline memory analysis. Monitor for unauthorized local access attempts and implement audit logging.
Quick answers
What is CVE-2026-27875?
Upgrade Johnson Controls Simplex Incident Manager to version v2.01.01 or later. Restrict local access to authorized personnel only. Implement endpoint protection and monitoring to detect memory-dumping tools or suspicious processes. Enforce strong access control policies and the principle of least privilege on host systems. Utilize full-disk encryption and secure boot to reduce the risk of offline memory analysis. Monitor for unauthorized local access attempts and implement audit logging.
How severe is CVE-2026-27875?
medium, CVSS 5.8
Is CVE-2026-27875 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-27875 be mitigated?
Upgrade Johnson Controls Simplex Incident Manager to version v2.01.01 or later. Restrict local access to authorized personnel only. Implement endpoint protection and monitoring to detect memory-dumping tools or suspicious processes. Enforce strong access control policies and the principle of least privilege on host systems. Utilize full-disk encryption and secure boot to reduce the risk of offline memory analysis. Monitor for unauthorized local access attempts and implement audit logging.
CVSS
5.8
Vendor
Johnson Controls Inc.
Published
Sep 30, 2026 · 08:42
Patch
Unknown / not confirmed
Affected products
Johnson Controls Simplex Incident Manager
Mitigation
Upgrade Johnson Controls Simplex Incident Manager to version v2.01.01 or later. Restrict local access to authorized personnel only. Implement endpoint protection and monitoring to detect memory-dumping tools or suspicious processes. Enforce strong access control policies and the principle of least privilege on host systems. Utilize full-disk encryption and secure boot to reduce the risk of offline memory analysis. Monitor for unauthorized local access attempts and implement audit logging.
The Cybersecurity and Infrastructure Security Agency (CISA) has issued an Industrial Control Systems advisory regarding a vulnerability in Johnson Controls Simplex Incident Manager that stores user credentials in cleartext within system memory. Successful exploitation could allow a local attacker with low privileges to extract sensitive authentication data, potentially leading to unauthorized access to the application and connected systems. No known public exploitation has been reported at this time.