The US Cybersecurity and Infrastructure Security Agency has issued an advisory after independent maritime researchers reported critical flaws in Wärtsilä’s voyage‑planning software, the latest instance of third‑party disclosure in the sector.
Cydome’s maritime cyber research team reported that two critical vulnerabilities exist in Wärtsilä FOS‑Onboard version 5.07.0923.01. The company published its findings to prompt action and to inform operators running the affected release.
CISA recorded the matter as advisory ICSA‑26‑258‑XX and listed the faults under CVE‑2026‑78225 and CVE‑2026‑81855. The advisory rates the flaws as critical; one entry carries a CVSS v4 score of 9.5, with the other designated critical in the published notice.
Wärtsilä describes its Fleet Optimisation Solution, often abbreviated FOS, as voyage and fleet operations software and states it is in use on thousands of ships. That deployment footprint makes vulnerability notices such as CISA’s of immediate operational interest to a wide span of commercial shipping.
The advisory and Cydome’s disclosure together set out the component versions and identifiers that owners and managers need to check. Operators running the specified FOS‑Onboard release are the intended audience for the published guidance.
Official advisory and researcher disclosure
CISA’s ICSA‑26‑258‑XX advisory provides the formal notice and vulnerability identifiers that naval administrators and IT teams rely on when assessing risk. The notice links the two CVE entries to the FOS‑Onboard release named by Cydome.
Cydome’s maritime cyber team conducted the analysis and reported the vulnerabilities to public attention, triggering the US agency’s formal advisory. The coordinated disclosure path is the mechanism described in the advisory and in the researcher summary.
What operators need to know
The public material identifies the affected product and the precise build number reported by the researchers. Wärtsilä’s own description of FOS as a voyage and fleet operations tool, and its stated presence on thousands of vessels, accentuates the need for fleet IT and shipboard teams to verify installed versions.
Administrators should compare their deployed FOS‑Onboard version with the release cited by the researchers and follow any mitigation steps or updates the vendor or CISA recommend. The advisory and researcher brief together provide the identifiers needed to match affected instances in shipboard and shore‑side systems.
The notice that at least one vulnerability has a CVSS v4 score of 9.5 signals high severity under the industry scoring framework. CISA’s advisory frames the vulnerabilities as critical, which typically leads to prioritised remediation work in fleet cyber programmes.
Supply chain and operational planners will want to ensure that both shore and on‑board software inventories are accurate, and that changes are coordinated with vessel schedules. Because Wärtsilä states the software is used at scale, verification across fleets may be a substantial administrative task.
CISA, Cydome and Wärtsilä are named in the materials that have been circulated; the advisory number and CVE identifiers provide the concrete references technical teams use to confirm whether their installations are affected. The combined release of a researcher report and a federal advisory is the current source for factual detail on the matter.
Technical teams and senior managers will now have to weigh the advisory guidance against operational constraints and update plans for affected vessels. The known product version and the advisory identifiers are the principal facts on which any remediation timeline should be built.