CISA flags critical Wärtsilä FOS flaws after Cydome disclosure
CISA published an advisory on two critical vulnerabilities in Wärtsilä’s Fleet Optimisation Solution after Cydome’s maritime cyber team found flaws that could let remote attackers push unauthorized updates and execute code. Wärtsilä says it has developed a patch, and operators are being told to update and tighten network controls.
Why it matters: - The flaws could let a remote unauthorized user gain a trusted foothold in Wärtsilä Fleet Optimisation Solution, then manipulate operational data or move into connected OT and IT systems. - The advisory raises the risk of vessel disruption, compliance problems and financial damage if the software is compromised. - CISA classified the issues as critical, with CVSS v4 scores of 9.5 and 9.3.
What happened: - Cydome’s maritime cyber research team identified critical vulnerabilities in Wärtsilä FOS-Onboard version 5.07.0923.01. - CISA published advisory ICSA-26-258-02 covering CVE-2026-78225 and CVE-2026-81855. - Wärtsilä confirmed to CISA that it developed a security patch for users. - The discovery was handled through a responsible disclosure process via CISA.
The details: - The vulnerabilities involve a hard-coded cryptographic key in components of the FOS software. - Exploitation could allow unauthorized updates to the FOS system. - Attackers could execute code on the system. - Attackers could extract credentials and impersonate a privileged client. - Wärtsilä’s Fleet Optimisation Solution is voyage and fleet operations software. - Wärtsilä describes itself as a leading marine equipment and systems provider and says its solutions are installed on one in every three vessels sailing the oceans. - Wärtsilä’s marine business includes engines, propulsion and fuel supply equipment, marine navigation, fleet optimization and simulation solutions. - Wärtsilä is quoted in the advisory as saying the vulnerabilities are not exploitable when the product is installed as recommended. - Users are directed to contact Wärtsilä to obtain and install the patch. - Cydome says this is its 9th CVE and the 3rd maritime product line it has published vulnerabilities in this year, after issues in Metis devices and NAVTOR NavBox. - Cydome also points to its maritime CVE disclosures.
Between the lines: - Maritime OT remains an underexamined target even though shipping carries about 90% of the world’s goods. - Cydome argues that specialized shipboard systems and a shortage of researchers leave the sector with few published CVEs. - The company says generative AI is lowering the barrier for attackers and that OT cyber incidents rose 150% in 2025, based on its research. - Cydome says rising ship connectivity through LEO services such as Starlink is expanding the attack surface for critical OT assets. - The advisory is also a signal that secure installation and patch management still matter, but so do segmentation, access control and continuous monitoring.
What operators should do now: - Operators should immediately deploy the latest patch that fixes the vulnerabilities. - Operators should segment operational elements and OT away from IT networks. - Operators should block unauthorized remote access. - Operators should run ongoing vulnerability scans to catch known critical issues before attackers exploit them. - Operators should use active cybersecurity monitoring, including intrusion detection systems that can spot abnormal maritime OT traffic and potential zero-day activity.
What's next: - Wärtsilä users should contact the company to obtain and install the patch. - Operators will likely need to verify their FOS deployments against the recommended installation guidance. - Maritime fleets may face more scrutiny of OT exposure as vendors and researchers publish additional CVEs. - Cydome says it will continue proactive research to identify threats before they disrupt operations.
The bottom line: - Critical flaws in a widely used maritime operations platform can become vessel-level risks fast, which makes patching, segmentation and continuous monitoring the immediate priorities.
Disclaimer: This article was produced by AGP Wire with the assistance of artificial intelligence based on original source content and has been refined to improve clarity, structure, and readability. This content is provided on an “as is” basis. While care has been taken in its preparation, it may contain inaccuracies or omissions, and readers should consult the original source and independently verify key information where appropriate. This content is for informational purposes only and does not constitute legal, financial, investment, or other professional advice.
Sign up for:
Cryptocurrency Insider Today
The daily local news briefing you can trust. Every day. Subscribe now.
Check Your Email!
We sent a one-time activation link to: .
Confirm it's you by clicking the email link.
If the email is not in your inbox, check spam or try again.
Welcome back!
is already signed up. Check your inbox for updates.