CVE-2026-75112Disclosure

MEDIUMCVSS 6.9 · MEDIUM

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

A security issue exists within OTTO® Fleet Manager. The vulnerability stems from the use of an insufficient work factor in the bcrypt password hashing implementation, which could reduce the computational cost required for an attacker to perform offline brute-force attacks against stored password hashes. If an attacker gains access to an unencrypted system backup, the weakly hashed credentials could be more easily compromised.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-916

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-08-19); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-08-19: 1Mentions · 2026-08-28: 1Mentions · 2026-08-29: 1Active Exploitation · 2026-08-28: 1Patch / Workaround · 2026-08-29: 1Technical Details · 2026-08-19: 1Technical Details · 2026-08-28: 1Technical Details · 2026-08-29: 108-1908-2808-29
Signal classification3 categories
Disclosure
133.3%
Active Exploitation
133.3%
Patch
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-08-191
Disclosure1
2026-08-281
Active Exploitation1
2026-08-291
Patch1
Full discourse3 posts
  • NewsTongue@NewsTongueX
    Patch

    🔴 Rockwell Automation patches weak password hashing in OTTO Fleet Manager Rockwell Automation addressed CVE-2026-75112 in OTTO Fleet Manager v2.36.3, a vulnerability affecting the company's fleet management software deployed worldwide in critical manufacturing and transportation. The flaw: insufficient work factor in bcrypt password hashing, allowing attackers with access to unencrypted system backups to more easily brute-force stored password hashes offline. The vulnerability is not remotely exploitable and no known public exploitation has been reported. Users unable to upgrade should enable encrypted system backups per advisory SD1791.

    Post summary

    Rockwell Automation released a patch for CVE-2026-75112, detailing a weak bcrypt password hashing flaw and recommending encrypted backups for users who cannot upgrade; no active exploitation has been reported.

    0000045
    811 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers exploiting CVE-2026-75112 can crack Rockwell Automation OTTO Fleet Manager password hashes with reduced computational effort. Compromised fleet credentials enable lateral movement into operational technology networks controlling autonomous vehicle systems. Runtime segmentation helps contain post-compromise activity in industrial environments. #ZeroTrust #CloudSecurity 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/rockwell-automation-otto-fleet-manager-cve-2026-75112-password-hash-vulnerability

    Post summary

    The analysis confirms attackers are actively exploiting CVE‑2026‑75112 to crack Rockwell Automation OTTO Fleet Manager password hashes, enabling lateral movement in OT networks while runtime segmentation limits post‑compromise activity.

    0000052
    2.0K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-75112 Weak Bcrypt Hashing in OTTO® Fleet Manager Enables Offline Brute-Force Attacks https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-75112

    Post summary

    The message announces CVE‑2026‑75112 in OTTO Fleet Manager, highlighting weak bcrypt hashing that permits offline brute‑force attacks, but provides no details on exploitation, patches, or proofs of concept.

    00000113
    4.1K followersView on X

Explore more