- What is CVE-2026-78225?
- Wärtsilä has developed a security patch for the affected version. Users are directed to contact Wärtsilä to obtain and install the latest patch via https://www.wartsila.com/services-catalogue/engine-services-4-stroke/wartsila-ics-patch-deployment#contact. CISA recommends minimizing network exposure for control system devices, ensuring they are not internet-accessible, locating control system networks behind firewalls and isolating them from business networks, and using secure remote access methods such as VPNs when remote access is required. Organizations should perform impact analysis and risk assessment prior to deploying defensive measures.
- How severe is CVE-2026-78225?
- critical, CVSS 9.3
- Is CVE-2026-78225 known to be exploited?
- It is not marked known-exploited in this record.
- How should CVE-2026-78225 be mitigated?
- Wärtsilä has developed a security patch for the affected version. Users are directed to contact Wärtsilä to obtain and install the latest patch via https://www.wartsila.com/services-catalogue/engine-services-4-stroke/wartsila-ics-patch-deployment#contact. CISA recommends minimizing network exposure for control system devices, ensuring they are not internet-accessible, locating control system networks behind firewalls and isolating them from business networks, and using secure remote access methods such as VPNs when remote access is required. Organizations should perform impact analysis and risk assessment prior to deploying defensive measures.