vulnerability Johnson Controls Simplex Incident Manager A critical vulnerability in Johnson Controls Simplex Incident Manager allows a local attacker with low privileges to extract user credentials (passwords and authentication tokens) from system memory, potentially leading to unauthorized access to the application and connected systems. The vulnerability affects versions… CISA Advisories · Aug 20, 2026 Critical CVE-2026-27875memory-dumpingcredential theftbuilding automation