What happened
CISA published an advisory on August 27, 2026, regarding a vulnerability in Rockwell Automation's OTTO Fleet Manager. The vulnerability, identified as CVE-2026-75112, stems from the use of password hashes with insufficient computational effort. Successful exploitation could reduce the computational cost required for an attacker to perform offline brute-force attacks against stored password hashes.
The advisory states that the following versions are affected: OTTO Fleet Manager <=V2.36.2. The CVSS v3 base score is 6.8. The advisory lists Critical Manufacturing and Transportation Systems as the critical infrastructure sectors where the product is deployed.
Why it matters
This vulnerability could allow attackers to more easily crack password hashes, potentially gaining unauthorized access to OTTO Fleet Manager systems. Given the product's deployment in critical manufacturing and transportation sectors, exploitation could disrupt operations or compromise sensitive data. Organizations using affected versions should review the advisory and consider mitigations.