THE CISA advisory (ICSA-26-239-03) dated August 27, 2026, from Rockwell Automation addresses a vulnerability in the OTTO Fleet Manager (versions ≤ V2.36.2). This vulnerability (CVE-2026-75112) allows attackers to exploit insufficient computational effort in password hashing, potentially enabling offline brute-force attacks on stored password hashes. The advisory indicates that Rockwell Automation has released an updated version (2.36.3) that mitigates the issue.
The advisory highlights the importance of minimizing network exposure and implementing security best practices to protect critical infrastructure sectors such as manufacturing and transportation.