# Wärtsilä offers patch for critical fleet software vulnerabilities

_Published Thursday, October 1, 2026 at 11:08 AM EDT · Security · Latest · Tier 2 — Notable_

Wärtsilä has developed a patch for two critical vulnerabilities in FOS-Onboard version 5.07.0923.01, according to Cydome research published by Hellenic Shipping News Worldwide. CISA's advisory covers CVE-2026-78225 and CVE-2026-81855, with CVSS v4 scores of 9.5 and 9.3 respectively.

The flaws involve a hard-coded cryptographic key and could let unauthorized remote users deliver updates, execute code or extract credentials to impersonate a privileged client. FOS supports voyage and fleet operations and, Wärtsilä says, is used on thousands of ships. Wärtsilä told CISA the vulnerabilities are not exploitable when the product is installed as recommended. Users must contact the company to obtain and install the patch.

## Sources

- [Hellenic Shipping News Worldwide](https://www.hellenicshippingnews.com/cisa-publishes-its-first-wartsila-advisory-after-cydome-finds-critical-flaw-in-wartsilas-fos-software/)

---
Canonical: https://techandbusiness.org/newswire/-7PCj_sPXIUVR_JVwBiKeh
Published: 2026-10-01T15:08:39.719Z
Story chronology: 2026-09-28T23:59:00.000Z
Retrieved: 2026-10-01T18:17:22.350Z
Publisher: Tech & Business (techandbusiness.org)
