Security1 distinct publisher2 min readPublished
Rockwell set bcrypt's work factor too low in OTTO Fleet Manager, so anyone who lifts an unencrypted system backup gets cheaper offline cracking, and the 2.36.3 fix does nothing for backups already written.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
The operative verb in CISA's summary is reduce: successful exploitation lowers the computational cost of offline brute force against stored password hashes [1]. That reduction alone doesn't hand over access; the stated precondition is that an attacker already holds an unencrypted system backup [3], which puts CVE-2026-75112 among the bugs that price the second move of an intrusion rather than the first [16].
CISA files it as CWE-916, use of a password hash with insufficient computational effort [5], and the root cause is the work factor chosen for the bcrypt implementation [10]. Everything up to and including V2.36.2 is affected [2]. The fix is 2.36.3 [4], a patch-level increment on the same minor line [14], so the change-window argument for deferring it is thin.
The upgrade only protects credentials going forward. The advisory does not say whether installing 2.36.3 rehashes credentials already written to disk [13], and the remediation list contains no credential rotation step at all [12]. Hashes inside a backup are whatever the version that wrote them produced, so an archive taken from a 2.36.2 install still carries low-work-factor hashes after the live system is current [15]. If those backups are retained for a year, the exposure lasts a year, and its size is a function of how many copies exist and who can read them.
The other half of the remediation is configuration rather than code. Rockwell's SD1791 carries instructions for enabling encrypted system backup in OTTO Fleet Manager [6], and that control outlives this CVE, because it is what makes the next hashing mistake uninteresting.
The advisory's omissions are worth reading. Its metrics section publishes no CVSS score [11], and CISA records no known public exploitation specifically targeting the flaw [8]. Rockwell reported the issue to CISA itself [7], so the disclosure path looks like internal review rather than a response to something found in the field. Deployment is worldwide, in critical manufacturing and transportation systems [9], which is why this arrives with an ICS advisory number [17] instead of a release note.
For a site whose OTTO backups are already encrypted at rest and sit behind an access list someone can recite from memory, this is a routine upgrade and little else. For a site keeping unencrypted system backups on a general-purpose file share, the patch is the cheap part, and the work that actually closes the hole is rotating every credential the fleet manager holds and destroying the old archives.
Ranked by verification strength, evidence, and original report placement.
CISA states that if an attacker gains access to an unencrypted system backup, the weakly hashed credentials could be more easily compromised.
The relevant weakness class is CWE-916, use of password hash with insufficient computational effort.
The vulnerability stems from the use of an insufficient work factor in the bcrypt password hashing implementation in OTTO Fleet Manager.
CISA states that successful exploitation of this vulnerability could reduce the computational cost required for an attacker to perform offline brute-force attacks against stored password hashes.
Rockwell Automation OTTO Fleet Manager versions up to and including V2.36.2 are affected, tracked as CVE-2026-75112.
Rockwell Automation has addressed the vulnerability in software version 2.36.3.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 27, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
Rockwell found weak password hashing in its own robot fleet supervisor1 distinct publisher
security
CISA finally counts the water intrusions: 100-plus exposed systems behind cellular modems2 distinct publishers
security
CISA revises the Mitsubishi FA advisory a fourth time for one UDP denial-of-service bug1 distinct publisher
product
The UK plant that went dark for four days was too small to have to tell anyone1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Authoritative but single-source and technically thin
Every factual claim traces to a first-party CISA ICS advisory based on the vendor's own report, which is about as authoritative as disclosure sourcing gets for affected versions, root cause, CWE class, and fix version. It is nonetheless one document with no corroborating report, no CVSS score or vector, and no disclosure of the actual or corrected bcrypt work factor, so severity and magnitude cannot be independently checked. The story's most pointed element - that already-written backups stay weak - is an inference from documented silence rather than a stated fact.
No uptake or exposure data
The supplied material shows that a fix exists (2.36.3) and that deployments span critical manufacturing and transportation systems worldwide, but it contains no install-base count, no patch-uptake figure, no telemetry, and no exploitation observations. There is no basis to score real-world adoption of either the affected product or the remediation without inferring numbers the advisory does not provide.
Framing runs slightly ahead of the advisory
The core of the story matches the advisory closely, and it is candid about the missing CVSS, the missing rotation step, and the silence on rehashing. The framing still leans further than the source: calling every unencrypted backup a credential file, and asserting the fix does nothing for backups already written, converts documented absence into stated consequence, while the advisory's own qualifiers - not remotely exploitable, no known public exploitation, attacker must already hold a backup - narrow the practical severity. The gap is modest and directional rather than a misstatement.
Vendor-led self-disclosure with vendor-held detail
Rockwell Automation reported the flaw to CISA itself, which aligns publisher and vendor interests in a low-drama presentation: no CVSS score is assigned, the work factor values are not disclosed, and the operationally important instructions - enabling encrypted system backup - sit behind the vendor's own SD1791 advisory rather than in the public document. CISA as publisher has no commercial stake and the advisory does carry the unflattering root cause plainly, which limits how far incentives distort the record.
High on facts, moderate on consequence
Confidence in the documented facts is high because they come verbatim from a primary government advisory sourced to the vendor. Confidence in the story's central consequence is only moderate: it depends on an inference about pre-existing backups that the advisory neither confirms nor denies, and the absence of any severity metric, work factor value, or deployment data means the practical scale of the risk cannot be pinned down from this material alone.