Hospital fire alarm software leaks credentials from memory, CISA warns

CISA flags a credential-leaking flaw in the software hospitals use to manage Simplex fire alarm systems.

MedRisk Staff
By
2 Min Read

Software used to manage Simplex fire alarm and life-safety systems, a fixture of hospital campuses across the country, can let a low-privileged local attacker pull credentials straight out of system memory.

CISA published an advisory on August 20 covering CVE-2026-27875, a vulnerability in Johnson Controls Simplex Incident Manager versions 2.01 and earlier. The flaw allows an attacker with low privileges to extract user credentials, including passwords and authentication tokens, from memory, which could lead to unauthorized access to the application and connected systems. The advisory rates the issue 5.8 on the CVSS v3 scale.

Simplex is one of the most widely installed fire alarm and life-safety product lines in healthcare, and Incident Manager is the console operators use to respond to alarms and track incidents. Credential theft from that console gives attackers a starting point to pivot into wider hospital networks, where they can reach patient records and clinical systems.

CISA recommends updating to a patched version, limiting local access to workstations, and monitoring for suspicious activity. Because these systems often sit on building-management segments shared with HVAC and other operational technology, facility and security teams should treat them as part of the clinical attack surface rather than isolated fire-safety appliances.

Share This Article