Cyber Resilience
← All news
Confirmed

Wärtsilä FOS-Onboard

Our takeCISA reports active exploitation in Wärtsilä FOS-Onboard 5.07.0923.01 that could let attackers push unauthorized updates, run code, or steal credentials. Patch immediately if you run these OT systems.
Sources (1)
What this means for you — Security leader:CISA reports active exploitation in Wärtsilä FOS-Onboard 5.07.0923.01 (CVEs-2026-78225 and -81855). These allow unauthorized updates, code execution, and credential theft for client impersonation; apply the vendor patch immediately if you operate these systems, especially in OT/ICS environments.
What this means for you — Lean IT orgs:If your operations use Wärtsilä FOS-Onboard version 5.07.0923.01, contact your equipment vendor or integrator right away for the available patch — these flaws let attackers run code or steal credentials.
What this means for you — MSP:Check client OT/ICS estates for any Wärtsilä FOS-Onboard 5.07.0923.01 deployments. CISA reports active exploitation allowing code execution and credential theft; prioritize patching or isolation where present.
What this means for you — Researcher:CISA advisory ICSA-26-258-02 details two actively exploited vulnerabilities in Wärtsilä FOS-Onboard 5.07.0923.01 that enable unauthorized updates, remote code execution, and credential extraction for privileged impersonation.