Rently Smart Home versions 20.1.0 and prior contain an insufficiently protected credentials vulnerability (CVE-2026-75960). Exploitation allows an attacker to retrieve sensitive pins, including the Master Pin, and override standard user permissions. The vendor has patched the vulnerability in late June.
credential-exposure
2 posts
Rently Smart Home (CVE-2026-75960) Johnson Controls Simplex Incident Manager (CVE-2026-27875) Johnson Controls Simplex Incident Manager versions V2.01 and earlier are vulnerable to cleartext storage of sensitive information in memory (CVE-2026-27875). A local attacker with low privileges can extract user credentials and authentication tokens from system memory using memory-dumping tools, potentially leading to unauthorized access to the application and connected systems.