Cyber Resilience
← All news
Confirmed

Rockwell Automation OTTO Fleet Manager

Our takeCISA reports active exploitation of a flaw in Rockwell Automation OTTO Fleet Manager <=2.36.2 that lowers the cost of offline brute-force attacks on stored password hashes. OT operators: patch it now.
Sources (1)
What this means for you — Security leader:CISA reports active exploitation of a flaw in Rockwell Automation OTTO Fleet Manager <=2.36.2 that reduces the cost of offline brute-force attacks against stored password hashes. Update to a fixed version and treat any OTTO Fleet Manager credentials as potentially compromised.
What this means for you — Lean IT orgs:If you run Rockwell Automation OTTO Fleet Manager (version 2.36.2 or older), update it now. This flaw makes it easier for attackers to crack stored passwords.
What this means for you — MSP:Check client environments for Rockwell Automation OTTO Fleet Manager <=2.36.2 and apply the vendor update. The vulnerability lowers the effort needed for offline password cracking.
What this means for you — Researcher:CISA reports active exploitation of CVE-2026-75112 in Rockwell Automation OTTO Fleet Manager <=2.36.2. It reduces computational cost for offline brute-force attacks on stored password hashes.