CISA disclosed two critical vulnerabilities in Wärtsilä FOS-Onboard, fleet-management software used aboard vessels, after the flaws were reported by maritime cybersecurity firm Cydome Security. CVE-2026-78225, rated 9.1 to 9.5 depending on scoring version, is a hardcoded cryptographic server key in the software’s Update Controller component that could let an attacker deliver an unauthorized software update or execute code on affected systems.
A second flaw, CVE-2026-81855, is a hardcoded client authentication key in a robot-testing-framework component that could let an attacker extract credentials and impersonate a privileged client. Wärtsilä said the vulnerabilities are not exploitable under its recommended installation configuration and has made a patch available to customers on request. CISA lists the affected sector as Transportation Systems, with deployment worldwide.
Why it matters
Hardcoded keys are a recurring failure mode in operational technology because they can’t be rotated the way a normal credential can — once exposed, every deployed unit sharing that key is affected until firmware is patched.

Leave a Reply