CISA Issues Advisory on Critical Wärtsilä FOS Vulnerabilities
News related to:Wärtsilä · 2 min read
LONDON, UNITED KINGDOM, September 28, 2026 /CourierPR/ -- CISA has published its first advisory related to Wärtsilä’s Fleet Optimisation Solution (FOS), following critical vulnerabilities discovered by Cydome’s maritime cyber research team. The vulnerabilities, identified in Wärtsilä FOS-Onboard version 5.07.0923.01, could allow remote unauthorized users to deliver unauthorized updates to and execute code on the FOS system. CISA published the advisory as ICSA-26-258-02, covering CVE-2026-78225 and CVE-2026-81855, with CVSS v4 scores of 9.5 and 9.3, respectively.
Wärtsilä has confirmed to CISA that it has developed a security patch, which is now available to its users. The vulnerabilities involve the use of a hard-coded cryptographic key in components of the FOS software. Exploitation of these vulnerabilities could allow a remote unauthorized user to deliver unauthorized updates to the FOS system, execute code, or extract credentials to impersonate a privileged client. The most direct consequence of such an attack could be the ability of an attacker to gain a persistent trusted foothold in the FOS system, replacing it with a contaminated version without the operator’s knowledge. This access allows attackers to manipulate operational data, gain access to other operational technology (OT) or information technology (IT) systems connected to the FOS system, potentially risking the operation of the vessel, compliance violations, and financial damage.
Wärtsilä, a leading equipment and systems provider for the marine industry, claims to have solutions installed on one in every three vessels sailing the oceans. Its marine business provides engines, propulsion and fuel supply equipment, as well as marine navigation, fleet optimization, and simulation solutions. Despite the critical nature of these vulnerabilities, very few people are looking at maritime operational technology (OT). According to Cydome, having no published vulnerabilities is not unusual in this sector. While 90% of the world’s goods travel by sea, maritime vessels operate highly specialized systems, especially OT, which require a high level of expertise that few possess. Advanced generative AI tools may lower the bar for cyber attackers, but maritime OT cyber research remains largely a blind spot within the cybersecurity community, with very few published Common Vulnerabilities and Exposures (CVEs).
Cydome, a pioneer in research-led cybersecurity for maritime and critical infrastructure operations, conducted proactive research to identify threats and vulnerabilities before they disrupt operations.
Operators are advised to take immediate action to prevent the exploitation of these vulnerabilities. They should ensure the latest patch is deployed, implement proper network segmentation, restrict unauthorized remote access, conduct ongoing vulnerability scanning, and employ active cybersecurity monitoring using an intrusion detection system. Cydome developed multi-layered cyber protection for maritime vessels, rather than adapting office IT tools for the job.
Wärtsilä's response to the findings stated that the vulnerabilities are not exploitable when the product is installed as recommended, and the company has developed a security patch. Users are directed to contact Wärtsilä to obtain and install the patch.