Johnson Controls Simplex Incident Manager versions V2.01 and earlier are vulnerable to cleartext storage of sensitive information in memory (CVE-2026-27875). A local attacker with low privileges can extract user credentials and authentication tokens from system memory using memory-dumping tools, potentially leading to unauthorized access to the application and connected systems.
CVE-2026-27875
1 post
Johnson Controls Simplex Incident Manager (CVE-2026-27875)