Latest with AI
Wednesday, September 30, 2026
Article

CISA publishes first Wärtsilä advisory after Cydome finds critical flaws in Wärtsilä’s FOS software

The flaws could enable remote, unauthorized users to push unapproved updates to the FOS system and run code on it.

“Even though the maritime sector is vital to the global economy, cybersecurity research in this area is limited—particularly when it comes to maritime-specific operational technology (OT).”— Alon Ayalon, VP R&D Cydome

Cydome’s maritime cyber research team has uncovered critical security flaws in Wärtsilä FOS-Onboard version 5.07.0923.01. Wärtsilä’s Fleet Optimisation Solution (FOS) is a voyage and fleet operations software suite. CISA issued advisory ICSA-26-258-02 covering CVE-2026-78225 and CVE-2026-81855, which are rated as critical vulnerabilities (CVSS v4 scores of 9.5 and 9.3, respectively). Wärtsilä has informed CISA that it has created a security patch now available to its customers.

The vulnerabilities involve a hard-coded cryptographic key used in parts of the FOS software. If exploited, they could allow a remote, unauthorized user to deliver unapproved updates to the FOS system, execute code, or extract credentials that would let the attacker impersonate a privileged client.

The most immediate risk is that an attacker could gain a persistent, trusted foothold in the FOS system, essentially swapping it out for a tampered version without the operator realizing it. This level of access would let attackers alter operational data, reach other OT or IT systems linked to the FOS platform, and potentially jeopardize vessel operations, lead to compliance violations, and cause financial losses.

First Published Wärtsilä Vulnerability
Wärtsilä is a top provider of equipment and systems for the marine industry, claiming its solutions are installed on one out of every three ships worldwide. Its marine business supplies engines, propulsion and fuel delivery equipment, as well as marine navigation, fleet optimization, and simulation tools, among other offerings.

Despite its impact, very few people are looking at maritime OT
Not having any published vulnerabilities is not unusual in this industry. Although 90% of global goods are transported by sea, vessels operate highly specialized maritime systems—especially maritime operational technology (OT). Cybersecurity research and the compromise of marine OT demand a high level of expertise that few possess. While advanced generative AI tools lower the barrier for cyber attackers and risks are becoming more pronounced (Cydome research found that OT cyber incidents in 2025 increased by 150%), maritime OT cyber research remains largely a blind spot in the cybersecurity community, with very few published CVEs—including the CVEs published earlier this year by the Cydome research team.

“Given the maritime industry’s importance to the global economy and the potential risk to shipping from cyber threats, cybersecurity research in this field is scarce—especially when it comes to maritime-specific operational technology (OT). To help the industry become more resilient to rapidly evolving risks, Cydome conducts and publishes proactive research to identify threats and vulnerabilities before they can disrupt operations.”
Alon Ayalon, CTO and Co-Founder, Cydome

What operators should do now
Exploits of this vulnerability—and similar severe flaws in maritime OT—should be prevented by taking the following steps:
1. Operators should immediately update by deploying the latest patch that fixes the vulnerabilities.
2. Implement proper network segmentation that separates operational elements and OT from IT.
3. Ensure no unauthorized remote access is allowed.
4. Proactively run ongoing vulnerability scanning to prevent known critical vulnerabilities from being exploited.
5. Employ active cybersecurity monitoring using an intrusion detection system that can identify abnormal maritime OT network traffic to discover threats that manage to bypass other defenses or exploit a vulnerability that hasn’t been published yet (Zero Day).

Cydome developed multi-layered cyber protection for maritime vessels rather than adapting office IT tools for the job.
“Maritime operations are transforming with hyper-connectivity through LEO technologies such as Starlink. But this digitalization, combined with the rapid adoption of AI, also expands the attack surface of critical OT assets. Cyber risk can no longer be managed reactively; organizations need continuous, active risk management embedded into their operational processes to protect vessels and the systems they depend on, and not rely on legacy solutions to protect their OT.” said Ayalon. “Operators should not wait for a CVE to identify gaps in their cybersecurity; they should proactively deploy protection and continuously manage their cyber risks.” he added.
Alon Ayalon, CTO and Co-Founder, Cydome

The flaw in the Wärtsilä software was discovered and shared through a responsible disclosure process via CISA. It is the 9th CVE and the 3rd maritime product line that Cydome’s research team has published vulnerabilities for this year, following CVEs in Metis devices and NAVTOR NavBox.

Wärtsilä Response To The Findings
As part of the CISA advisory, Wärtsilä is quoted as saying that the vulnerabilities are not exploitable when the product is installed as recommended, and it has developed a security patch. Users are also directed to contact Wärtsilä to obtain and install the patch.

About Cydome
Cydome is a pioneer in research-led cybersecurity for maritime and critical infrastructure operations. Its products and managed services utilize Cydome’s proactive cyber research and advanced AI technologies to provide fleet-wide monitoring, protection, threat prevention and integrated risk management for complex operations at sea. Trusted by leading maritime organizations and classification societies, Cydome protects vessels and offshore facilities around the world.

For additional maritime CVEs published by Cydome research, please see: https://cydome.io/cve

Shahar Dumai
Cydome
marketing@cydome.io
Visit us on social media:
LinkedIn
YouTube