SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-27875

MEDIUM · CVSS 6.9 EPSS 0.07%

Source: NVD + CISA KEV + EPSS · Published 2026-08-21 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The vulnerability in Johnson Controls Simplex Incident Manager and Autocall Fire Administrator prior to version 2.01.05 allows attackers to access sensitive data stored in cleartext in memory, potentially compromising confidential information. Organizations using these products should prioritize remediation to mitigate the risk of data exposure and ensure compliance with security best practices.

CVE
CVE-2026-27875
Severity
MEDIUM
CVSS
6.9
EPSS
0.07%

Original NVD Description

Cleartext Storage of Sensitive Information in Memory vulnerability in Johnson Controls Simplex Incident Manager / Autocall Fire Administrator may allow an attcker to Retrieve Embedded Sensitive Data. This issue affects Simplex Incident Manager / Autocall Fire Administrator: before 2.01.05.