Executive summary

CISA published on August 20, 2026 advisory ICSA-26-232-01 warning of a vulnerability in Johnson Controls Simplex Incident Manager, the BMS module that manages fire alarms, physical security events, regulatory reporting and incident response coordination in critical buildings, including hospitals. The vulnerability, CVE-2026-27875, allows a local low-privilege attacker to extract credentials and authentication tokens directly from the process memory, opening the door to lateral movement toward the BMS and integrated systems. CVSS v3.1 6.7 (MEDIUM), vector AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:L; CVSS v4.0 confirms MEDIUM severity with exploitability AT:P (Attack Prerequisite — specific conditions required). Johnson Controls has released version v2.01.01 with the patch. The vulnerability is local (not remotely exploitable) and requires prior authentication, but in a hospital the Simplex Incident Manager is typically located on physical security workstations and Control Rooms with multiple internal operators, which lowers the exploitation barrier.

Key points

  • Affected product: Johnson Controls Simplex Incident Manager, Simplex BMS component dedicated to alarm, event and regulatory reporting management.
  • Affected version: Simplex Incident Manager <=V2.01 (patch available: v2.01.01). Update to v1.01.05 or later is also recommended for older lines.
  • CVE and vector: CVE-2026-27875 — cleartext storage of sensitive information in memory (CWE-316). CVSS v3.1 6.7 (MEDIUM), vector AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:L. Local exploitation with low privileges and high complexity.
  • Attack vector: a user with a valid local account (security operator, maintenance technician with support account) can execute process memory dumping tools to extract passwords and authentication tokens from the application. With those credentials they can authenticate against other BMS components and connected systems.
  • Potential clinical impact: if the attacker escalates to other Johnson Controls BMS modules (climate control, smoke detection, access control, CCTV), they can disable fire alarms, manipulate audit logs (critical evidence for fire safety regulatory inspections) or bypass physical access controls to restricted areas such as pharmacy, neonatal ICU or laboratory.
  • Immediate mitigations: patch to v2.01.01, restrict local access to Simplex Incident Manager workstations, enforce MFA, enable full disk encryption and secure boot, apply least privilege on host accounts, monitor memory dumping processes.
  • CISA sectors: Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Transportation Systems, Energy. Healthcare not explicitly listed but Simplex is used in hospitals for alarm management and regulatory reporting.
  • No public exploit known at the time of the advisory; exploitation requires specific local prior conditions.

Regulatory implications

FDA (US)

Although Simplex Incident Manager is not an FDA-regulated medical device, hospitals in the US are subject to The Joint Commission and NFPA 72 (fire alarms) and NFPA 99 (healthcare). Manipulation of the alarm management system can compromise compliance with these standards and should be notified as an incident affecting patient safety.

MDR (EU)

If the BMS controls environmental conditions of medical devices or critical areas (ICU, OR, pharmacy), manipulation of alarms may constitute a serious MDR incident under Art. 87 MDR (≤15 days) and MDCG 2019-16 rev 1, especially if it compromises detection of environmental failures that put patient life at risk.

GDPR

Theft of credentials of BMS operators can expose personal data of healthcare staff (Art. 4 GDPR) and, depending on user roles, health data (Art. 9). Notification to DPA within 72h if compromise is confirmed (Art. 33).

NIS2 / ENS

Hospitals are essential entities under NIS2. Compromise of a physical security and fire detection alarm management system triggers obligations under Art. 21 NIS2 (risk management) and, in Spain, RD 311/2024 (ENS, HIGH category, op.cont.4).

HIPAA

Although Simplex Incident Manager does not directly store PHI, extraction of credentials from a user with access to the corporate network can facilitate lateral movement toward EHR/HIS systems and indirectly compromise PHI under §164.308 (administrative safeguards) and §164.312 (technical safeguards).

Recommendation

Immediate actions within the next 72 hours: (1) identify all instances of Simplex Incident Manager in the hospital (including older v1.x versions); (2) update to v2.01.01 (v2 line) or v1.01.05 (v1 line) as appropriate; (3) restrict physical and logical access to workstations running Simplex Incident Manager (only authorized security and maintenance personnel); (4) enforce MFA on all host accounts running the application; (5) enable full disk encryption (FDE) and secure boot on all stations to reduce the risk of offline forensic analysis of memory; (6) deploy EDR with detection of memory dumping tools (Mimikatz, ProcDump, comae-tools) on BMS stations; (7) audit privileged accounts on the host and apply the principle of least privilege; (8) review Simplex Incident Manager authentication logs from the last 90 days looking for anomalous accesses or out-of-hours use of administrative accounts.

30-day actions: document Simplex Incident Manager in the OT/IT inventory, integrate it into the central SOC with alerts on credential extraction patterns, and run an incident response drill simulating compromise of BMS credentials.


Source: CISA ICSA-26-232-01 — Johnson Controls Simplex Incident Manager

This analysis is part of HealthSec, the weekly newsletter on healthcare cybersecurity.