HomeIntelligenceBrief
VULNERABILITY BRIEF 🔴 Critical Vulnerability

Critical Hard‑coded Key Vulnerabilities (CVE‑2026‑78225, CVE‑2026‑81855) in Wärtsilä FOS‑Onboard Threaten Maritime Control Systems

Two CVEs expose a hard‑coded server key in Wärtsilä FOS‑Onboard (v5.07.0923.01), allowing unauthorized updates, code execution, and credential extraction. The flaw scores 9.1 on CVSS and requires immediate patching to maintain compliance and audit readiness.

Verisq™ Intelligence · 📅 September 15, 2026 · 📰 cisa.gov
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
cisa.gov

Critical Hard‑coded Key Vulnerabilities (CVE‑2026‑78225, CVE‑2026‑81855) in Wärtsilä FOS‑Onboard Threaten Maritime Control Systems

What It Is – Two CVEs disclose a hard‑coded cryptographic server key in the deployer‑ng Update Controller component of Wärtsilä FOS‑Onboard (version 5.07.0923.01). The flaw enables an attacker to deliver unauthorized software updates, execute arbitrary code, or extract credentials to impersonate a privileged client.

Exploitability – CVSS v3.1 base score 9.1 (Critical). No public exploits are known, and Wärtsilä states the issue is not exploitable when the product is installed per the vendor’s recommended configuration. A security patch has been released.

Affected Products – Wärtsilä FOS‑Onboard 5.07.0923.01 (industrial‑control software used in transportation‑system vessels worldwide).

Why It Matters for Trust & Control Assurance

  • Demonstrates the need for continuous monitoring of cryptographic controls and patch status across OT assets – a core control objective that satisfies multiple frameworks (e.g., NIST CSF 2.0 Identify and Protect).
  • Provides concrete evidence that a hard‑coded key can undermine the integrity of update mechanisms, highlighting gaps in configuration‑management and change‑control processes.
  • Enables organizations to prove due‑diligence to regulators and customers by documenting timely remediation and retaining verifiable audit trails.

Recommended Actions

  1. Obtain and apply Wärtsilä’s security patch immediately; verify the removal of the hard‑coded key.
  2. Update your asset inventory and configuration‑management database to reflect the patched version.
  3. Capture patch‑installation evidence in your control‑mapping repository to support audit readiness.

Source: CISA Advisory – ICSA‑26‑258‑02

📰 Original Source
https://www.cisa.gov/news-events/ics-advisories/icsa-26-258-02

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Vulnerability exposure

Is this CVE in your supply chain?

Verisq matches published vulnerabilities against the software your vendors run, so you know which relationships this touches before the next review.

See vendor exposure →