Critical Vulnerabilities Patched in Wärtsilä Fleet Software

The patches address two high-severity flaws that could allow remote code execution in maritime software.

Updated on Sept. 28, 2026 in Cybersecurity

Bold flat-color editorial illustration in navy, cream, and red, depicting the geometric structural form of an industrial maritime radar console.
Wärtsilä has released security patches for its FOS-Onboard maritime software following the discovery of two high-severity vulnerabilities by Cydome researchers. AI Illustration. Upload story photo >

Live Poll

Do you trust that maritime shipping systems are adequately protected against modern cyber threats?

CISA has issued an advisory regarding two critical vulnerabilities in Wärtsilä FOS-Onboard software version 5.07.0923.01. The flaws, identified by the Cydome research team, could allow unauthorized remote code execution or credential extraction.

Why it matters

These vulnerabilities highlight the rising security risks in operational technology (OT), where maritime systems are increasingly targeted. The industry saw a 150% increase in OT cyber incidents during 2025, underscoring the necessity of rapid patching for critical infrastructure.

The vulnerabilities include CVE-2026-78225, which carries a 9.5 CVSS v4 score, and CVE-2026-81855, rated at 9.3. These scores measure severity on a scale where 10 is the most critical.

The players

CISA

The Cybersecurity and Infrastructure Security Agency is a U.S. federal authority that coordinates national efforts to understand, manage, and reduce risk to cyber and physical infrastructure.

Wärtsilä

A global provider of smart technologies and complete lifecycle solutions for the marine and energy markets, focusing on vessel efficiency and decarbonization.

Cydome

A cybersecurity firm specializing in marine-specific threat intelligence and research, focused on protecting maritime operational technology and shipboard systems.

The details

The flaws stem from the use of a hard-coded cryptographic key—a permanent, unchangeable security password embedded within the software code—which leaves system components vulnerable. By exploiting this, unauthorized remote users can bypass security controls to execute malicious code or extract sensitive credentials. Wärtsilä has developed a security patch to remediate these specific entry points.

Timeline

  1. 2025: Operational technology cyber incidents increased by 150%.

  2. 2026: Cydome research team published multiple CVEs throughout the year.

  3. 2026-09-28

    CISA published advisory ICSA-26-258-XX regarding the vulnerabilities.

The Tech Race

This incident aligns with the 150% increase in OT cyber incidents observed in 2025 as attackers move to exploit specialized infrastructure. It follows a year of heightened scrutiny, during which Cydome published nine separate CVEs to address weaknesses in maritime software stacks.

Operators using Wärtsilä FOS-Onboard version 5.07.0923.01 should immediately apply the security patch developed by the manufacturer. Failure to update the software leaves shipboard systems exposed to remote code execution risks.

The takeaway

The maritime sector is facing an urgent need to modernize patch management protocols to counter sophisticated remote exploits. Organizations should track the implementation of these specific patches against CISA ICSA-26-258-XX to ensure system integrity.

Further reading

For broader trends in infrastructure protection, explore our Cybersecurity section.

Source note: This article includes information reported by Hellenic Shipping News.

Live Poll

Do you trust that maritime shipping systems are adequately protected against modern cyber threats?

Critical Vulnerabilities Patched in Wärtsilä Fleet Software | Highwise Tech