Upgrade to OTTO Fleet Manager version 2.36.3 or later. Enable encrypted system backup as described in Rockwell Automation security advisory SD1791. If unable to upgrade, follow Rockwell's security best practices and minimize network exposure of control system devices. Use VPNs for remote access and isolate control system networks from business networks.
Quick answers
What is CVE-2026-75112?
Upgrade to OTTO Fleet Manager version 2.36.3 or later. Enable encrypted system backup as described in Rockwell Automation security advisory SD1791. If unable to upgrade, follow Rockwell's security best practices and minimize network exposure of control system devices. Use VPNs for remote access and isolate control system networks from business networks.
How severe is CVE-2026-75112?
medium, CVSS 6.8
Is CVE-2026-75112 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-75112 be mitigated?
Upgrade to OTTO Fleet Manager version 2.36.3 or later. Enable encrypted system backup as described in Rockwell Automation security advisory SD1791. If unable to upgrade, follow Rockwell's security best practices and minimize network exposure of control system devices. Use VPNs for remote access and isolate control system networks from business networks.
CVSS
6.8
Vendor
Rockwell Automation
Published
Sep 30, 2026 · 08:05
Patch
Unknown / not confirmed
Affected products
OTTO Fleet Manager
Mitigation
Upgrade to OTTO Fleet Manager version 2.36.3 or later. Enable encrypted system backup as described in Rockwell Automation security advisory SD1791. If unable to upgrade, follow Rockwell's security best practices and minimize network exposure of control system devices. Use VPNs for remote access and isolate control system networks from business networks.
A medium-severity vulnerability in Rockwell Automation's OTTO Fleet Manager (versions <=2.36.2) allows attackers with access to unencrypted system backups to more easily brute-force stored password hashes due to an insufficient work factor in the bcrypt implementation. The vendor has released version 2.36.3 to address the issue and recommends enabling encrypted backups.