Security researchers disclosed two hard-coded-key issues in Wärtsilä FOS-Onboard 5.07.0923.01, with a vendor patch available through Wärtsilä.
Maritime cybersecurity company Cydome has disclosed two hard-coded cryptographic-key issues affecting Wärtsilä FOS-Onboard version 5.07.0923.01. The findings are tracked as CVE-2026-78225 and CVE-2026-81855 and were reported to Wärtsilä through a coordinated disclosure process involving CISA.
CVE-2026-78225 concerns an unencrypted RSA private key included with the deployer-ng Update Controller, while CVE-2026-81855 concerns a key and client certificate in the DMS robot testing framework. Cydome says Wärtsilä has developed a security patch and advises users to contact the vendor to obtain and install it.
Wärtsilä’s Fleet Operations Solution brings navigational, operational and technical vessel data into a connected platform used on board and ashore. The wider FOS environment can support voyage planning, route optimisation, reporting, performance monitoring and integration with bridge systems.
That level of integration is precisely why software configuration and update mechanisms matter on sophisticated vessels. A vulnerability advisory does not by itself establish that a yacht has been compromised, and operators should distinguish confirmed software exposure from evidence of an actual incident.
The immediate practical step for an operator using the affected version is to establish whether that version is installed and obtain Wärtsilä’s patch through the approved support channel. Yacht managers should also verify that network segmentation, firewall rules, remote-access controls and update procedures match the vendor’s recommended deployment.
Security teams should preserve configuration records and confirm the software inventory rather than making assumptions from vessel type or age. Where an onboard system is maintained by an external integrator, the captain and technical manager should ensure that responsibility for patching is explicitly assigned and documented.
Superyachts increasingly rely on connected navigation, communications, automation and remote-support systems that bridge operational technology and shoreside services. That brings operational benefits, but it also makes disciplined software lifecycle management part of normal vessel maintenance.
The FOS advisories are therefore relevant beyond a single product release. Owners, managers and captains benefit from knowing which systems are installed, who maintains them, how security advisories are received and how quickly critical vendor patches can be assessed and deployed.
Explore
Go deeper into the yachts, companies, events and destinations directly connected to this article.
Continue reading
NEGU has launched an IACS E26-focused remote-access service that moves vendor connections to a controlled shore-side jump host instead of onboard PCs.
Marlink has launched an operational-technology security offering for connected vessel systems, targeting risks around navigation, propulsion, HVAC, access control and other operational equipment.
Bureau Veritas has granted Cyber Security Type Approval to Inmarsat Maritime’s NexusWave bonded multi-network service against IACS UR E27.
There is no verified public evidence that AZZAM carries a missile system. Official Lürssen and Nauta material documents the yacht’s design and performance but …
Superyacht Guide
Continue into the wider Superyacht Guide.