CVE-2026-27875Active Exploitation

MEDIUMCVSS 6.9 · MEDIUM

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Cleartext Storage of Sensitive Information in Memory vulnerability in Johnson Controls Simplex Incident Manager / Autocall Fire Administrator may allow an attcker to Retrieve Embedded Sensitive Data. This issue affects Simplex Incident Manager / Autocall Fire Administrator: before 2.01.05.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-316

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-21: 2Active Exploitation · 2026-08-21: 1Patch / Workaround · 2026-08-21: 1Technical Details · 2026-08-21: 208-21
Signal classification2 categories
Active Exploitation
150.0%
Patch
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • Alon Nachmany@AlonNachmany
    Patch

    Quieter, but patch it: Johnson Controls Simplex Incident Manager stores credentials in cleartext. A local attacker can lift passwords and tokens from memory (CVE-2026-27875). Fix is out, v2.01.01. http://cisa.gov/news-events/ics-advisories/icsa-26-232-01 https://t.co/DhSBMRx7bO

    Post summary

    Johnson Controls Simplex Incident Manager is vulnerable due to cleartext credentials; a local attacker can extract passwords and tokens (CVE‑2026‑27875). A patch (v2.01.01) and a CISA advisory are already available.

    0000091
    67 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers exploiting CVE-2026-27875 in Johnson Controls fire safety systems to extract cleartext credentials from memory, then pivoting to connected building automation networks. Runtime segmentation helps contain lateral movement across critical infrastructure systems. #ICS #ZeroTrust 🔗 Full breakdown: https://aviatrix.ai/threat-research-center/johnson-controls-simplex-incident-manager-cve-2026-27875-memory-credential-exposure

    Post summary

    Analysis shows attackers actively exploiting CVE‑2026‑27875 to pull cleartext credentials from Johnson Controls fire safety system memory, enabling lateral movement to connected building automation networks, with no mention of patches or PoC code.

    0000070
    1.9K followersView on X

Explore more