Executive Summary
Johnson Controls Simplex Incident Manager versions 2.01 and earlier contain a critical vulnerability (CVE-2026-27875) that stores user credentials including passwords and authentication tokens in unencrypted form within system memory. This cleartext storage vulnerability allows local attackers with low privileges to extract sensitive authentication data using memory-dumping tools, potentially leading to unauthorized access to fire safety systems and connected critical infrastructure. The vulnerability affects fire safety management systems deployed worldwide across critical manufacturing, commercial facilities, government services, transportation systems, and energy sectors. Johnson Controls has released patched version 2.01.01 to address this security flaw and recommends immediate upgrades along with enhanced access controls and endpoint monitoring.
This incident highlights the growing concern over insecure credential management in industrial control systems as threat actors increasingly target OT environments. With fire safety systems being critical infrastructure components, credential exposure vulnerabilities pose significant risks to facility security and emergency response capabilities.
Why This Matters Now
Fire safety systems are increasingly targeted by threat actors seeking to disrupt critical infrastructure operations, and credential exposure vulnerabilities in these systems create immediate risks to facility security and emergency response capabilities during a time of heightened OT security threats.
Attack Path Analysis
The attack begins with an attacker gaining local access to a system running Johnson Controls Simplex Incident Manager through social engineering or insider access. Once local access is established, the attacker uses memory-dumping tools to extract cleartext credentials and authentication tokens from system memory due to CVE-2026-27875. With stolen credentials, the attacker moves laterally to other connected building automation systems and industrial control networks. Command and control channels are established to maintain persistent access across the industrial network. Sensitive operational data and credentials are exfiltrated to external systems. Finally, the attacker disrupts critical building automation systems, potentially affecting HVAC, fire safety, and security systems across facilities.
Kill Chain Progression
Initial Compromise
Description
Attacker gains local access to system running Simplex Incident Manager through social engineering, insider threat, or physical access to workstation
Related CVEs
CVE-2026-27875
CVSS 5.8Johnson Controls Simplex Incident Manager stores user credentials in cleartext within system memory, allowing local attackers with low privileges to extract passwords and authentication tokens.
Affected Products:
Johnson Controls Inc. Simplex Incident Manager – <= V2.01
Exploit Status:
no public exploit
MITRE ATT&CK® Techniques
OS Credential Dumping: /proc/pid/mem
Credentials from Password Stores: Credentials from Web Browsers
Valid Accounts: Local Accounts
Data Staged: Local Data Staging
Process Discovery
System Information Discovery
Abuse Elevation Control Mechanism: Setuid and Setgid
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Sensitive Authentication Data Protection
Control ID: 3.3.1
NYDFS 23 NYCRR 500 – Encryption of Nonpublic Information
Control ID: 500.15
CISA ZTMM 2.0 – Identity and Credential Management
Control ID: ID.AM-2
DORA – ICT Risk Management Framework
Control ID: Article 8
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
ISO 27001:2022 – Password Management System
Control ID: A.9.4.3
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Critical Manufacturing
Johnson Controls Simplex Incident Manager vulnerability exposes manufacturing facility credentials in memory, enabling unauthorized access to critical production control systems.
Government Administration
Government facilities using affected fire safety systems face credential extraction risks, potentially compromising building security and emergency response capabilities.
Energy
Energy infrastructure relying on Simplex systems vulnerable to local privilege escalation attacks that could extract authentication tokens for power facility access.
Transportation
Transportation hubs and facilities with Johnson Controls fire management systems at risk of credential theft leading to unauthorized building system control.
Sources
- Johnson Controls Simplex Incident Managerhttps://www.cisa.gov/news-events/ics-advisories/icsa-26-232-01Verified
- Johnson Controls Product Security Advisory JCI-PSA-2026-28https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisoriesVerified
- CISA ICS Security Recommended Practiceshttps://www.cisa.gov/icsVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF would likely constrain this building automation system attack by limiting lateral movement between industrial networks and reducing the attacker's blast radius across connected facilities.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Initial workstation compromise may still occur, but CNSF policies would likely limit the attacker's ability to enumerate and discover connected building automation systems across the network infrastructure
Control: Zero Trust Segmentation
Mitigation: Memory-based credential extraction may still succeed locally, but zero trust policies would likely limit the scope and effectiveness of stolen credentials across segmented building automation network zones
Control: East-West Traffic Security
Mitigation: Lateral movement between building automation systems would likely be significantly constrained through micro-segmentation policies that restrict communication paths between industrial control network segments and require explicit authorization for cross-zone access
Control: Multicloud Visibility & Control
Mitigation: Command and control channel establishment would likely be constrained through enhanced visibility and monitoring that detects suspicious communication patterns across the distributed building automation infrastructure and limits unauthorized network connections
Control: Egress Security & Policy Enforcement
Mitigation: Data exfiltration attempts would likely be significantly reduced through controlled egress policies that restrict outbound connections from building automation systems and require explicit authorization for external data transfers
Operational disruption to critical building systems would likely be limited to specific segmented zones, reducing the overall impact on HVAC, fire safety, and security controls across the broader facility infrastructure
Impact at a Glance
Affected Business Functions
- Fire Safety Management Systems
- Building Security Operations
- Emergency Response Coordination
- Critical Infrastructure Monitoring
Estimated downtime: 2 days
Estimated loss: N/A
User credentials including passwords and authentication tokens for building management systems, potentially affecting access control to critical infrastructure across multiple sectors including manufacturing, transportation, and energy facilities.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to isolate industrial control systems and prevent lateral movement between building automation networks using identity-based policies and microsegmentation
- • Deploy Encrypted Traffic capabilities to protect credentials and authentication tokens in transit, preventing interception during lateral movement across industrial networks
- • Enable East-West Traffic Security monitoring to detect and block unauthorized lateral movement between building automation systems and workload-to-workload communications
- • Implement Egress Security & Policy Enforcement to prevent exfiltration of sensitive industrial control data and block unauthorized outbound communications from critical infrastructure systems
- • Deploy Threat Detection & Anomaly Response capabilities to identify suspicious memory access patterns, credential extraction attempts, and anomalous behavior in industrial control environments



