← Back to Feed

Rockwell Automation OTTO Fleet Manager

CVE-2026-75112

August 27, 2026 · CISA (US-CERT) · Severity: CRITICAL

View CSAF Summary Successful exploitation of this vulnerability could reduce the computational cost required for an attacker to perform offline brute-force attacks against stored password hashes. The following versions of Rockwell Automation OTTO Fleet Manager are affected: OTTO Fleet Manager <=V2.36.2 (CVE-2026-75112) CVSS Vendor Equipment Vulnerabilities v3 6.8 Rockwell Automation Rockwell Automation OTTO Fleet Manager Use of Password Hash With Insufficient Computational Effort Background Critical Infrastructure Sectors: Critical Manufacturing, Transportation Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-75112 A security issue exists within OTTO Fleet Manager. The vulnerability stems from the use of an insufficient work factor in the bcrypt password hashing implementation, which could reduce the computational cost required for an attacker to perform offline brute-force attacks against stored password hashes. If an attacker gains access to an unencrypted system backup, the weakly hashed credentials could be more easily compromised. View CVE Details Affected Products Rockwell Automation OTTO Fleet Manager Vendor:Rockwell Automation Product Version:Rockwell Automation OTTO Fleet Manager: <=V2.36.2 Product Status:known_affected Remediations MitigationRockwell Automation has addressed this vulnerability in software version 2.36.3.https://file-share.ottomotors.com/login MitigationUsers of the affected software who are not able to upgrade to the corrected version or apply the mitigations should use Rockwell Automation's security best practices.https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight Vendor fixSee Rockwell Automation security advisory SD1791 for more information about this issue and instructions to enable encrypted system backup in OTTO Fleet...

Key Takeaways

  • CISA published an advisory for Rockwell Automation OTTO Fleet Manager urging users to apply vendor patches and mitigations.
  • Organizations using Rockwell Automation OTTO Fleet Manager should review CISA's advisory and apply security updates promptly.
  • Active exploitation of vulnerabilities in Rockwell Automation OTTO Fleet Manager has been reported, making patching urgent for affected organizations.
☕ Buy a Coffee