
🔴 Rockwell Automation patches weak password hashing in OTTO Fleet Manager Rockwell Automation addressed CVE-2026-75112 in OTTO Fleet Manager v2.36.3, a vulnerability affecting the company's fleet management software deployed worldwide in critical manufacturing and transportation. The flaw: insufficient work factor in bcrypt password hashing, allowing attackers with access to unencrypted system backups to more easily brute-force stored password hashes offline. The vulnerability is not remotely exploitable and no known public exploitation has been reported. Users unable to upgrade should enable encrypted system backups per advisory SD1791.
Post summary
Rockwell Automation released a patch for CVE-2026-75112, detailing a weak bcrypt password hashing flaw and recommending encrypted backups for users who cannot upgrade; no active exploitation has been reported.


