Cyber Resilience
← All news
Confirmed

Rockwell Automation OTTO Fleet Manager

Our takeCISA reports active exploitation of a flaw in Rockwell Automation OTTO Fleet Manager <=2.36.2 that lowers the computational cost of offline brute-force attacks on stored password hashes. OT operators: patch it now.
Sources (1)
What this means for you — Security leader:CISA reports active exploitation of CVE-2026-75112 in Rockwell Automation OTTO Fleet Manager <=2.36.2, which lowers the computational cost of offline brute-force attacks on stored password hashes. OT/ICS operators: apply the vendor patch immediately and review password storage practices.
What this means for you — Lean IT orgs:If you run Rockwell Automation OTTO Fleet Manager (version 2.36.2 or older), update it now. This flaw makes it easier for attackers to crack stored passwords.
What this means for you — MSP:Check client environments for Rockwell Automation OTTO Fleet Manager <=2.36.2 and schedule patching. The vulnerability reduces the effort needed for offline brute-force attacks against password hashes.
What this means for you — Researcher:CISA added CVE-2026-75112 (Rockwell Automation OTTO Fleet Manager <=2.36.2) to its Known Exploited Vulnerabilities catalog. It lowers the cost of offline brute-force attacks on stored password hashes.