CISA publishes its first Wärtsilä advisory after Cydome finds critical flaw in Wärtsilä’s FOS software
Cydome’s maritime cyber research team has identified critical vulnerabilities in Wärtsilä FOS-Onboard version 5.07.0923.01. Wärtsilä’s Fleet Optimisation Solution (FOS) is a voyage and fleet operations software that Wärtsilä says is used on thousands of ships. CISA published the advisory as ICSA-26-258-XX covering CVE-2026-78225 and CVE-2026-81855, rated as critical vulnerabilities (CVSS v4…
The Center for Internet Security (CISA) has issued its first advisory regarding a critical vulnerability in Wärtsilä's FOS-Onboard software, identified by maritime cyber research team Cydome. This software, used in thousands of ships for voyage and fleet operations, contains vulnerabilities classified as critical (CVE-2026-78225 and CVE-2026-81855), with CVSS v4 scores of 9.5 and 9.3, respectively.
Wärtsilä has developed a security patch to address these vulnerabilities, which could enable unauthorized users to deliver updates, execute code, or extract credentials, posing a significant risk to vessel operations, data exposure, and even safety. The FOS software is a central component of vessel operations, connected to other critical systems.
Exploiting these vulnerabilities could allow remote attackers to manipulate vessel performance data or inject malicious code into connected critical systems, such as navigation, engine management, and fuel systems. Despite the severity of these vulnerabilities, maritime operational technology (OT) cybersecurity research remains relatively underexplored.
Cydome's research highlights the increasing number of OT cyber incidents in 2025, with a 150% rise, underscoring the need for enhanced cybersecurity measures in the maritime industry. Proactive protection measures are recommended, as exploiting these vulnerabilities can be challenging due to the specialized nature of maritime OT, often connected to IT networks and the public internet without proper monitoring.
Wärtsilä, a leading marine equipment provider, has confirmed the availability of the security patch and advised users to contact them for installation.
Written by urgent.news from Hellenic Shipping News's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.