Executive Summary
Critical vulnerabilities CVE-2026-78225 and CVE-2026-81855 were discovered in Wärtsilä FOS-Onboard version 5.07.0923.01, affecting maritime transportation systems worldwide. Both vulnerabilities involve hardcoded cryptographic keys - one in the deployer-ng Update Controller component and another in the robot testing framework component. With CVSS scores of 9.0 and 9.1 respectively, successful exploitation could allow attackers to deliver unauthorized updates, execute arbitrary code, or extract credentials to impersonate privileged clients. Wärtsilä has developed security patches and states the vulnerabilities are not exploitable when the product is installed according to recommendations.
This incident highlights the growing threat to maritime critical infrastructure as operational technology systems become increasingly connected and targeted by sophisticated adversaries seeking to disrupt global supply chains.
Why This Matters Now
Maritime systems are increasingly targeted as attack vectors for supply chain disruption, while hardcoded cryptographic vulnerabilities in critical infrastructure represent a fundamental security anti-pattern that enables persistent backdoor access across globally deployed systems.
Attack Path Analysis
Attackers exploited hardcoded cryptographic keys in Wärtsilä FOS-Onboard maritime systems to gain initial access, then leveraged these credentials to escalate privileges within the industrial control environment. They moved laterally through connected operational technology networks, established persistent command channels through compromised update mechanisms, exfiltrated sensitive operational data and credentials, and potentially disrupted critical maritime operations affecting vessel navigation and safety systems.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers exploited hardcoded cryptographic keys (CVE-2026-78225, CVE-2026-81855) in the deployer-ng Update Controller and robot testing framework components to gain unauthorized access to the maritime control system
Related CVEs
CVE-2026-78225
CVSS 9A hardcoded cryptographic server key vulnerability in the deployer-ng Update Controller component allows unauthorized update delivery and code execution.
Affected Products:
Wärtsilä FOS-Onboard – 5.07.0923.01
Exploit Status:
no public exploitCVE-2026-81855
CVSS 9.1A hardcoded cryptographic client authentication key vulnerability in the robot testing framework component allows credential extraction and client impersonation.
Affected Products:
Wärtsilä FOS-Onboard – 5.07.0923.01
Exploit Status:
no public exploit
MITRE ATT&CK® Techniques
Valid Accounts: Cloud Accounts
Unsecured Credentials: Credentials In Files
Credentials from Password Stores
Exploit Public-Facing Application
Hardware Additions
Data Manipulation: Stored Data Manipulation
Lateral Tool Transfer
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
NIST Cybersecurity Framework 2.0 – Criticality and Sensitivity of Data, Assets, and Functions
Control ID: ID.RA-09
CISA Zero Trust Maturity Model 2.0 – Authentication and Authorization
Control ID: Identity-2.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21.2(a)
DORA – ICT Risk Management Framework
Control ID: Article 8.2
ISO 27001:2022 – Use of Cryptography
Control ID: A.8.24
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Maritime
Critical vulnerability in Wärtsilä marine engine control systems exposes hardcoded cryptographic keys, enabling unauthorized updates and credential extraction in vessel operations.
Transportation
Marine transportation systems face severe risk from hardcoded authentication vulnerabilities allowing attackers to compromise vessel engine management and safety systems remotely.
Oil/Energy/Solar/Greentech
Offshore energy platforms using Wärtsilä systems vulnerable to critical authentication bypass attacks potentially disrupting power generation and extraction operations through compromised industrial controls.
Utilities
Power generation facilities utilizing Wärtsilä engine systems exposed to critical hardcoded key vulnerabilities enabling unauthorized system access and potential operational disruption.
Sources
- Wärtsilä FOS-Onboardhttps://www.cisa.gov/news-events/ics-advisories/icsa-26-258-02Verified
- Wärtsilä ICS Patch Deployment Serviceshttps://www.wartsila.com/services-catalogue/engine-services-4-stroke/wartsila-ics-patch-deployment#contactVerified
- Cydome Security Ltd - Vulnerability Researchhttps://cydome.comVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would constrain attacker movement through maritime operational technology networks by enforcing segmented access controls and limiting lateral expansion from compromised cryptographic keys. The fabric's east-west enforcement and controlled egress capabilities would likely reduce the blast radius across critical ship systems.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The fabric's identity-aware controls would likely constrain the scope of access achievable through compromised hardcoded keys, limiting the attacker's ability to impersonate legitimate services across the broader maritime control environment.
Control: Zero Trust Segmentation
Mitigation: Segmentation policies would likely limit the scope of privileged access by constraining which maritime control functions could be reached from compromised update controller credentials, reducing the attacker's ability to escalate across all ship systems.
Control: East-West Traffic Security
Mitigation: East-west traffic controls would likely constrain lateral movement between maritime operational technology networks, limiting the attacker's ability to reach engine management and navigation systems from initially compromised update components.
Control: Multicloud Visibility & Control
Mitigation: Visibility and control mechanisms would likely constrain the attacker's ability to maintain persistent command channels by monitoring and restricting anomalous communications through legitimate update pathways in the maritime environment.
Control: Egress Security & Policy Enforcement
Mitigation: Egress controls would likely constrain the volume and types of sensitive maritime data that could be extracted by enforcing data loss prevention policies and restricting outbound communications from operational technology networks.
The constrained attack scope would likely limit operational disruption to specific maritime system segments rather than enabling widespread impact across all vessel navigation and safety infrastructure simultaneously.
Impact at a Glance
Affected Business Functions
- Marine Engine Management Systems
- Fleet Operations Control
- Vessel Navigation Systems
- Engine Performance Monitoring
Estimated downtime: N/A
Estimated loss: N/A
Potential exposure of privileged client credentials and cryptographic keys that could allow unauthorized system access and control of marine engine management systems
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to isolate industrial control systems from corporate networks and limit lateral movement between operational technology components
- • Deploy Encrypted Traffic controls with MACsec/IPsec to protect data in transit between maritime control systems and prevent credential interception
- • Establish Egress Security & Policy Enforcement to monitor and control outbound communications from industrial systems, preventing unauthorized data exfiltration
- • Enable East-West Traffic Security with microsegmentation to restrict workload-to-workload communications within the maritime control environment
- • Implement Multicloud Visibility & Control with centralized monitoring to detect anomalous interactions and suspicious automation within industrial networks



