Government Advisory

Password Security Flaw Found in Rockwell Automation's OTTO Fleet Manager

CISA · 27 Aug 2026
Key Takeaway If your business uses Rockwell Automation OTTO Fleet Manager, check for vendor guidance or patches addressing this issue and review your password policies as an added precaution.

Cybersecurity authorities have identified a vulnerability in Rockwell Automation's OTTO Fleet Manager, a software product used in critical manufacturing and transportation industries worldwide. The flaw affects all versions up to and including V2.36.2 and relates to how the software stores password hashes.

The issue, tracked as CVE-2026-75112, means the software uses a password hashing method that doesn't require enough computational effort to protect against attacks. In practical terms, if an attacker managed to steal a copy of stored password data, they could crack those passwords through offline brute-force attempts far more easily and quickly than they should be able to. The vulnerability has been rated with a moderate CVSS score of 6.8.

While this vulnerability affects an industrial fleet management platform rather than typical office software, it serves as a useful reminder for all businesses. Weak password hashing is a common and often overlooked security gap, and any organisation relying on third-party software should stay alert to vendor security advisories and apply updates or mitigations promptly once available.

ICS Security Rockwell Automation Password Security Critical Infrastructure Vulnerability Advisory

Summarised by CISO AI from CISA. We link back to every original so you can read it yourself.