Johnson Controls Simplex Incident Manager

2026-08-20T19:23:20Z9c79e38aa57f0c016b6c677b41feee3320892d530e902c4538869e125b306156
CVE-2025-7639CVE-2026-19670CVE-2026-19671CVE-2026-27875CVE-2026-34491CVE-2026-55676CVE-2026-57262CVE-2026-57263CVE-2026-59086CVE-2026-63133CVE-2026-63134CVE-2026-63177CVE-2026-64629AVEVACISA ICS advisoryCISA MalcolmJohnson ControlsOT securitySCADASiemensbuffer overflowcredential exposurecritical infrastructuredenial of serviceindustrial control systemsremote code execution

What happened

CISA ICS advisories published August 13–20, 2026, covering vulnerabilities in Johnson Controls Simplex Incident Manager and Metasys, Siemens Simcenter Nastran, Parasolid, and LOGO! Soft Comfort, AVEVA Enterprise SCADA, and CISA Malcolm. Issues include credential exposure in memory, stack overflow and out-of-bounds read vulnerabilities, cryptographic weaknesses, unsafe deserialization, persistent cross-site scripting, path traversal, unrestricted uploads, authorization flaws, and denial-of-service conditions. Several vulnerabilities can enable arbitrary code execution, session hijacking, data—,

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cisa_ics_advisories
Record identifier
9c79e38aa57f0c016b6c677b41feee3320892d530e902c4538869e125b306156
Enrichment time
2026-08-20T19:23:20Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Johnson Controls Simplex Incident Manager · Baitaphish