Skip to content

CISA publishes its first Wärtsilä advisory after Cydome finds critical flaw in Wärtsilä's FOS software

Hellenicshippingnews • September 28, 2026

Cydome’s maritime cyber research team has identified critical vulnerabilities in Wärtsilä FOS-Onboard version 5.07.0923.01. Wärtsilä’s Fleet Optimisation Solution (FOS) is a voyage and fleet operations software that Wärtsilä says is used on thousands of ships. CISA published the advisory as ICSA-26-258-XX covering CVE-2026-78225 and CVE-2026-81855, rated as critical vulnerabilities (CVSS v4 scores of 9.5 and 9.3, respectively). Wärtsilä has confirmed to CISA that it has developed a security patch, available to its users.

The vulnerabilities involve the use of a hard-coded cryptographic key in components of the FOS software, and their exploitation could allow a remote unauthorized user to deliver unauthorized updates, execute code, or extract credentials to allow the attacker to impersonate a privileged client.

Given the severity of the vulnerabilities in a system central to the vessel operation and connected to additional, mission-critical systems, such exploitation could result in interruption to the normal operation of the vessel, exposure of operational information, and potentially serve as a stepping stone for other exploits onboard, potentially posing a safety risk as well. For example, a successful exploit could allow a remote attacker to manipulate vessel performance data provided by the FOS system, or use it as a stepping stone to inject malicious code into critical systems it’s connected to, such as the ship’s , engine management, fuel systems, etc.

First Published Wärtsilä Vulnerability

Wärtsilä is a leading equipment and systems provider for the marine industry, claiming to have solutions installed on one in every three vessels sailing the oceans. Its marine business provides (among others): engines, propulsion and fuel supply equipment as well as marine , fleet optimization and simulation solutions.

Despite its impact, very few people are looking at maritime OT

Having no published vulnerabilities is not unusual in this sector. While 90% of the world’s goods travel by sea, maritime vessels operate highly specialized maritime systems, especially maritime operational technology (OT). Cybersecurity research as well as the compromise of marine OT requires a high level of expertise that few possess. While advanced generative AI tools lower the bar for cyber attackers and risks becoming more prominent (Cydome research found that the number of OT cyber incidents in 2025 showed a 150% increase), maritime OT cyber research remains largely a blind spot within the cybersecurity community, with very few published CVEs – including the CVEs published earlier this year by the Cydome research team.

“Despite the importance of the maritime industry to the global economy and the potential risk to shipping from cyber threats, cyber research in this field is scarce – especially regarding maritime-specific operational technology (OT). To help the industry become more resilient to the fast-evolving risks, Cydome conducts and publishes proactive research to identify threats and vulnerabilities before they disrupt operations.”

Alon Ayalon, CTO and Co-Founder, Cydome

What operators should do now

Exploits of this vulnerability and similar severe vulnerabilities in maritime OT should be prevented by ensuring the following:

Operators should immediately update by deploying the latest patch that fixes the vulnerabilities.

Implement proper network segmentation that separates operational elements and OT from IT.

Ensure no unauthorized remote access is allowed.

Proactively run ongoing vulnerability scanning to prevent known critical vulnerabilities from being exploited.

Employ active cybersecurity monitoring using an intrusion detection system that can identify abnormal maritime OT network traffic to discover threats that manage to bypass other defenses or exploit a vulnerability that hasn’t been published yet (Zero Day).

Cydome developed multi-layered cyber protection for maritime vessels rather than adapting office IT tools for the job.

“Maritime OT is where we find many vulnerabilities. In many cases, we find OT equipment that is connected to the IT networks and even the public internet without proper monitoring, and this trend becomes even more pronounced as vessels become more connected,” said Ayalon. “Remote code execution in onboard OT systems can allow an attacker to access and even control critical vessel systems. In the absence of real-time onboard cyber monitoring, this access can remain undetected and might be discovered only after operational impact has occurred.” he added. ‘Operators should not wait for a CVE to identify gaps in their cybersecurity. They should proactively deploy protection that covers the entire vessel. This could make the difference between a fleet-wide emergency and a local incident.”

Alon Ayalon, CTO and Co-Founder, Cydome

The flaw in the Wärtsilä software was discovered and shared in a responsible disclosure process through CISA. It is the 9th CVE and the 3rd maritime product line Cydome’s research team has published vulnerabilities in this year, following CVEs in Metis devices and NAVTOR NavBox.

As part of the CISA advisory, Wärtsilä is quoted as stating that the vulnerabilities are not exploitable when the product is installed as recommended, and it has developed a security patch. Users are also directed to Wärtsilä to obtain and install the patch. To obtain and install the latest patch, Wärtsilä directly. Source: Cydome