WW/SUPPLYCHAI
CISA flags critical flaws in Wärtsilä fleet software used on thousands of ships
CISA published its first Wärtsilä advisory after Cydome disclosed critical flaws rated 9.5 and 9.3 on the CVSS v4 scale in the FOS fleet optimization software used on an estimated one in three ocean-going vessels.
- By
- Elena Vasquez
- Filed
- Length
- 618 words
- Read
- 3 min

Key points05
- CISA issued ICSA-26-258-XX covering CVE-2026-78225 and CVE-2026-81855, with CVSS v4 scores of 9.5 and 9.3
- Wärtsilä says its marine solutions are installed on one in every three ocean-going vessels
- Cydome reported a 150% increase in OT cyber incidents in 2025
- This is Cydome's ninth CVE and third maritime product line disclosure of 2026, following Metis and NAVTOR NavBox
- Wärtsilä confirmed a patch is available and is directing users to contact the company directly
The US Cybersecurity and Infrastructure Security Agency (CISA) has published its first-ever advisory for Wärtsilä after Cydome's researchers disclosed two critical flaws in the Finnish marine group's Fleet Optimisation Solution (FOS), rated 9.5 and 9.3 on the CVSS v4 scale.
Issued as ICSA-26-258-XX, the advisory covers CVE-2026-78225 and CVE-2026-81855 in Wärtsilä FOS-Onboard version 5.07.0923.01. Wärtsilä has confirmed a security patch is available and is directing users to obtain it directly from the company. CISA has yet to publish the advisory on its public website at the time of writing.
What the flaw exposes
Both vulnerabilities stem from a hard-coded cryptographic key inside FOS components. A remote, unauthorised attacker who exploits the bug can push unauthorised updates, execute code, and harvest credentials to impersonate a privileged client on the vessel network.
FOS sits at the centre of voyage and fleet operations, with connections running into navigation, engine management and fuel systems. Exploitation could interrupt vessel operations, expose operational data, or open a path into adjacent mission-critical systems, with attendant safety risk.
Why maritime OT stays a blind spot
Wärtsilä says its marine solutions ride aboard one in every three ocean-going vessels. Despite that installed base, and the fact that roughly 90% of the world's goods travel by sea, published CVEs against maritime operational technology (OT) remain thin on the ground.
Cydome, the Israeli firm that discovered the flaw through a responsible-disclosure process, counted a 150% increase in OT cyber incidents in 2025. Generative AI tooling, the company noted, is lowering the bar for attackers even as defenders struggle to find specialists fluent in vessel systems.
What operators should do now
Cydome's mitigation checklist for fleet operators reads as follows:
- Deploy the latest Wärtsilä patch immediately across affected FOS installations.
- Segment OT networks from corporate IT and from any public-internet-facing systems.
- Block unauthorised remote access paths into vessel networks.
- Run continuous vulnerability scanning rather than waiting for a published CVE.
- Layer active intrusion detection tuned for maritime OT traffic to surface zero-day activity.
Cydome's track record in 2026
This is Cydome's ninth CVE publication of the year and the third maritime product line the firm has targeted, following earlier disclosures against Metis devices and NAVTOR's NavBox. The Wärtsilä case marks the first time a Cydome finding has triggered a CISA advisory for a major engine and systems OEM.
What does the ruling change for shipowners?
In practical terms, the advisory pressures operators running FOS on tankers, container ships and bulk carriers to verify their patch status before the next port call. Wärtsilä's position, quoted in the CISA advisory, is that the vulnerabilities are not exploitable when the product is installed as recommended.
Cydome CTO and co-founder Alon Ayalon pushed back on that framing. "Maritime OT is where we find many vulnerabilities. In many cases, we find OT equipment that is connected to the IT networks and even the public internet without proper monitoring, and this trend becomes even more pronounced as vessels become more connected," he said.
Ayalon warned of remote code execution paths that can stay hidden without real-time onboard monitoring. "Operators should not wait for a CVE to identify gaps in their cybersecurity. They should proactively deploy protection that covers the entire vessel. This could make the difference between a fleet-wide emergency and a local incident," he said.
With CISA now naming Wärtsilä and the disclosures stacking up across three product lines in a single year, fleet operators should expect more Cydome-filed CVEs to escalate into federal advisories as the maritime OT research backlog clears.
Source: Hellenic Shipping News
More from Elena Vasquez
Show full bio
News editor covering industry trends and analytics at Waybill Wire.
262 articles
Related05
Höegh Autoliners rolls Marlink–NORMA Cyber defence across fleet
Marlink and NORMA Cyber link shipboard threat detection to incident response
BIMCO committees flag Hormuz security and fuel transition as top shipping risks
NMFTA flags 'skillful' cyber escalation to trucking industry
ICS widens free resource library with new checklists, 2025-26 barometer and carbon capture research