The Cybersecurity and Infrastructure Security Agency (CISA) has published an advisory (ICSA-26-258-XX) detailing critical cybersecurity vulnerabilities within Wärtsilä's Fleet Optimisation Solution (FOS) software, specifically version 5.07.0923.01 of FOS-Onboard. These flaws, identified by Cydome's maritime cyber research team, carry high CVSS v4 scores of 9.5 and 8.1, indicating severe potential impact. Wärtsilä's FOS is a widely adopted voyage and fleet operations software, reportedly utilized on thousands of ships globally.
For freight forwarders and operations managers, this development highlights the growing cyber risks within the maritime sector. A compromise of critical operational software like FOS could lead to significant disruptions in voyage planning, fleet management, and potentially impact vessel safety and schedule reliability. While the immediate impact on freight rates or capacity is not direct, any incident causing delays or re-routing due to cyber issues could have cascading effects on supply chains. Forwarders should encourage their shipping partners to ensure all vessel software is updated and robust cybersecurity measures are in place to mitigate such risks.
Ship operators using Wärtsilä FOS-Onboard version 5.07.0923.01 are advised to review CISA's recommendations and apply any available patches or mitigation strategies provided by Wärtsilä to address CVE-2026-78225 and CVE-2026-81855.

