---
title: "Superyacht Cyber Intelligence: Onboard Firewall Flaws Under Attack (Issue #018)"
description: The latest vulnerabilities affecting superyachts and what to do about them. MikroTik, firewalls, Starlink, backups and more.
image: https://trustanchorpoint.com/hubfs/Cover.png
---

[Skip to content](https://trustanchorpoint.com/insights/superyacht-cyintel-briefing-7-october-2026#main-content)

[![Anchorpoint logo black](https://trustanchorpoint.com/hs-fs/hubfs/Black-White.png?width=1100&height=300&name=Black-White.png)Homepage](https://trustanchorpoint.com)

- [What's a virtual CISO?](https://trustanchorpoint.com/whats-a-virtual-ciso)
- Superyacht Cybersecurity
  
    - [Hire a virtual Cybersecurity Officer (vCySO)](https://trustanchorpoint.com/cybersecurity-compliance-for-superyachts)
    - [Cybersecurity Compliance for Superyachts](https://trustanchorpoint.com/cybersecurity-compliance-for-superyachts)
    - [Cybersecurity Awareness Training for Superyacht Crew](https://trustanchorpoint.com/cybersecurity-awareness-training-for-superyacht-crew)
    - [Cybersecurity Threat Intelligence for Superyacht Crew](https://trustanchorpoint.com/cybersecurity-threat-intelligence-for-superyacht-crew)
- [Insights](https://trustanchorpoint.com/insights)
- [About](https://trustanchorpoint.com/about-us)
  
    - [Code of Ethics](https://trustanchorpoint.com/code-of-ethics)

[Contact us](https://trustanchorpoint.com/contact)

- [What's a virtual CISO?](https://trustanchorpoint.com/whats-a-virtual-ciso)
- Superyacht Cybersecurity
  
    - [Hire a virtual Cybersecurity Officer (vCySO)](https://trustanchorpoint.com/cybersecurity-compliance-for-superyachts)
    - [Cybersecurity Compliance for Superyachts](https://trustanchorpoint.com/cybersecurity-compliance-for-superyachts)
    - [Cybersecurity Awareness Training for Superyacht Crew](https://trustanchorpoint.com/cybersecurity-awareness-training-for-superyacht-crew)
    - [Cybersecurity Threat Intelligence for Superyacht Crew](https://trustanchorpoint.com/cybersecurity-threat-intelligence-for-superyacht-crew)
- [Insights](https://trustanchorpoint.com/insights)
- [About](https://trustanchorpoint.com/about-us)
  
    - [Code of Ethics](https://trustanchorpoint.com/code-of-ethics)

[Contact us](https://trustanchorpoint.com/contact)

![](https://trustanchorpoint.com/hs-fs/hubfs/Cover.png?width=1920&height=1080&name=Cover.png)

Cyber security Cybersecurity Superyachts

# Superyacht Cyber Intelligence: Onboard Firewall Flaws Under Attack (Issue #018)

![Matt](https://app.hubspot.com/settings/avatar/618f3d942fdcc567e50ece243104b38b)

 Matt

October 7, 2026

CyIntel - Bi-weekly briefing

A catch-up covering 29 July to 7 October 2026. Plain English first. Technical detail for whoever looks after your onboard systems sits under each section.

Issue: 7 October 2026 · Covers: 29 Jul to 7 Oct · Snapshot, check vendor pages for later changes

TL;DR

## The short version

Don't have the exact product named? Check the nearest equivalent. If it has not been updated since July, treat it as out of date.

1**Routers.** MikroTik: update RouterOS to 7.24.5 or later. Any other make: check when its firmware was last updated, and that its admin page cannot be reached from the internet, crew Wi-Fi or guest Wi-Fi.

2**Firewalls and VPN gateways.** Fortinet, Cisco and SonicWall have been actively attacked since July. Using something else (Palo Alto, Ubiquiti, Sophos, Kerio, WatchGuard)? Ask when it was last updated, and who still has remote access.

3**Starlink.** Keep the router admin away from crew and guest networks, and check the Starlink app for an update.

4**Laptops, phones and iPads.** Restart Chrome and Edge, and install pending Windows, Apple and Android updates. Crew devices count too.

5**Backups.** Veeam: confirm it is fully patched. A different backup tool: check when it was last updated. Either way, keep one copy off the main network and ask when a restore was last tested.

6**Bridge, cameras and onboard systems.** Confirm none of them can be reached from the internet. Look out for Siemens PLCs, Dahua cameras, Furuno AIS and Wartsila systems.

Not sure whether any of this applies to your vessel? Contact us and we will check it with you.

Priority 1 of 6

## MikroTik routers

Exploited Critical

### In plain English

MikroTik routers are common on yachts for crew Wi-Fi, guest networks and links to satellite and AV equipment. Two serious flaws have appeared in a month. The first lets an attacker get past the SSH login and is being used in attacks. The second, published on 1 October, lets someone take over the router through its web admin page with no password. No attacks on the second have been reported yet.

### What to do

- Ask your onboard technical person whether any MikroTik routers are on board, including inside other equipment.
- Have RouterOS updated to the latest stable release, 7.24.5 or later.
- Make sure the admin page cannot be reached from the internet or guest Wi-Fi.
- Contact IT support if unsure.

\+Technical detail for your onboard technical person Tap to open / close ▾

| Reference | Issue | Date | Fix and status |
| --- | --- | --- | --- |
| CVE-2026-67276 CVE-2026-86060 | SSH authentication bypass chain (six CVEs in total across SSH, bandwidth-test, X.509 and WebFig). Exploited in the wild. | 25 Sep | Fixed in 7.24.2, 7.23.4 and 6.49.21. |
| CVE-2026-84411 | Pre-authentication remote code execution as root in the web management service. CVSS 9.8. CISA advisory ICSA-26-272-06. RouterOS earlier than 7.24. | 1 Oct | Fixed in 7.24 or later, 7.24.5 reported as latest stable. No exploitation reported at publication. |
| CVE-2026-14227 | API session flaw exposes WireGuard VPN private keys. | 30 Jul | Update RouterOS. Rotate WireGuard keys if the API was exposed. |

**Actions:** inventory RouterOS versions and WAN exposure. Disable the www and www-ssl services or restrict them to a management VLAN. Back up the config, upgrade in a maintenance window, then retest VSAT, VPN and VLAN routing.

Priority 2 of 6

## Firewalls, VPN gateways and Wi-Fi

Exploited Critical

### In plain English

Attackers keep going after the devices between your vessel network and the internet. Fortinet, Cisco and SonicWall products all have flaws being used in attacks since July. Palo Alto and Ubiquiti have also released serious fixes, with no attacks reported on those.

### What to do

- Find out the make and model of your firewall, VPN gateway and Wi-Fi controller.
- Ask your provider to confirm each is on the latest vendor firmware.
- Check who has remote access and remove anyone who no longer needs it.
- Contact IT support if unsure.

\+Technical detail for your onboard technical person Tap to open / close ▾

| Reference | Issue | Date | Status |
| --- | --- | --- | --- |
| CVE-2025-25249 | Fortinet FortiOS and FortiSwitchManager CAPWAP heap overflow, unauthenticated remote code execution. | 9 Sep | Exploited, CISA KEV. |
| CVE-2026-76460 | Cisco ISE unauthenticated policy API authentication bypass. | 16 Sep | Exploited, Cisco and CISA KEV. |
| CVE-2026-20332 and others | Cisco Secure Firewall ASA, FTD and FMC hardening release, eight CVEs. | 16 Sep | At least two exploited, Cisco stated. |
| CVE-2026-20079 | Cisco Secure Firewall Management Center authentication bypass to root. CVSS 10.0. | 21 Sep | Exploited, CISA KEV 9 Sep. |
| CVE-2026-20349 | Cisco ASA and FTD remote access SSL VPN denial of service. | 11 Aug | Exploited, Cisco and CISA KEV. |
| CVE-2026-20316 | Cisco Secure Firewall Management Center static credentials. | 29 Jul | Exploited as a zero-day, CISA KEV. |
| CVE-2026-83548 CVE-2026-83549 | SonicWall SMA1000 pre-authentication SSRF chained to remote code execution. | 1 Sep | Exploited, CISA KEV. |
| CVE-2026-15409 CVE-2026-15410 | SonicWall SMA1000 SSRF and code injection. | 13 Aug | Exploited, ransomware use confirmed by CISA. |
| CVE-2026-0310 | Palo Alto PAN-OS buffer overflow, unauthenticated root code execution on PA-Series hardware. | 9 Sep | No exploitation known to the vendor as of 9 Sep. |
| CVE-2026-77550 and others | Ubiquiti UniFi Security Advisory Bulletin 067, unauthenticated UniFi OS authentication bypass. CVSS 10.0. | 26 Aug | No exploitation reported. |

**Actions:** inventory FortiGate, Cisco, SonicWall, Palo Alto and UniFi devices with versions. Patch internet-facing devices first, then management consoles. Review VPN and admin logins for unexpected activity since July. Treat any unpatched SMA1000 or FMC as urgent.

Priority 3 of 6

## Starlink Router Gen 3

Watch Public attack code

### In plain English

A weakness in the Starlink Router Gen 3 management interface has public attack code. At our last check on 15 August there was no fix from Starlink, and no attacks had been reported. Starlink is on almost every superyacht, so this is worth keeping an eye on.

### What to do

- Keep the Starlink router admin off guest and crew networks.
- Check the Starlink app for a router update.
- Contact IT support if unsure.

\+Technical detail for your onboard technical person Tap to open / close ▾

| Reference | Issue | Date | Status |
| --- | --- | --- | --- |
| CVE-2026-19918 | Starlink Router Gen 3 gRPC management interface access control weakness. | 15 Aug | Public proof of concept. Not in CISA KEV. No vendor fix at last check. |

**Actions:** restrict the management interface to a trusted VLAN. Check current Starlink release notes, as the fix status may have changed since 15 August.

Priority 4 of 6

## Laptops, phones and iPads

Exploited

### In plain English

Google Chrome has had two zero-day flaws used in attacks since September, and Microsoft has fixed Windows flaws that attackers were already using. Apple released large updates for iPhone, iPad and Mac. These are the easiest fixes on this list, and every crew and guest device is affected.

### What to do

- Restart Chrome and Edge so the update installs.
- Install pending Windows, iOS, iPadOS and macOS updates.
- Ask crew to update their own devices before connecting to the vessel network.
- Contact IT support if unsure.

\+Technical detail for your onboard technical person Tap to open / close ▾

| Reference | Issue | Date | Status |
| --- | --- | --- | --- |
| CVE-2026-85046 | Chrome V8 type confusion zero-day. | 3 Sep | Exploited, CISA KEV. |
| CVE-2026-87491 | Chrome 153 V8 zero-day, plus five critical WebGL and Cast flaws. | 8 Sep | Exploited, Google stated. |
| CVE-2026-33824 | Windows IKE Service Extensions unauthenticated remote code execution. | 18 Aug | Exploited in the wild. |
| September Patch Tuesday | Two Windows privilege escalation zero-days. | 8 Sep | Exploited, added to CISA KEV. |
| CVE-2026-65400 | macOS Screen Sharing pre-authentication remote root access. | 18 Aug | Exploited, CISA KEV. |
| iOS and iPadOS 26.7 | Cumulative update fixing 82 security issues. | 14 Sep | No exploitation reported by Apple. |

**Actions:** push or verify the Chrome and Edge version across managed endpoints, apply the September Windows updates, and roll out Apple 26.7. Disable macOS Screen Sharing where it is not needed.

Priority 5 of 6

## Backups

Public attack code Exploitation unconfirmed

### In plain English

Veeam, a widely used backup product, has had several serious fixes since July. Attackers going after a vessel with ransomware often try to destroy the backups first. Attack code is public for one of these flaws, though we have not seen confirmed attacks.

### What to do

- Ask your IT provider to confirm Veeam is fully updated.
- Check at least one backup copy is kept off the main network.
- Ask when a restore was last tested.
- Contact IT support if unsure.

\+Technical detail for your onboard technical person Tap to open / close ▾

| Reference | Issue | Date | Status |
| --- | --- | --- | --- |
| CVE-2026-32996 | Veeam Agent for Windows local privilege escalation to SYSTEM. Version 13.0.1.2067 and earlier version 13 builds. | 22 Sep | Public exploit. Third parties report likely exploitation, unconfirmed. |
| CVE-2026-58073 CVE-2026-58072 | Veeam Service Provider Console credential theft and remote code execution. | 4 Aug | No exploitation reported. |
| CVE-2026-64633 | Veeam ONE unauthenticated remote code execution. | 29 Jul | No exploitation reported. |

**Actions:** identify any Veeam ONE, VSPC and Agent deployments and patch them. Keep an immutable or offline copy. Restrict the backup server to a management network.

Priority 6 of 6

## Bridge, cameras and onboard systems

Exploited (cameras, PLCs) Watch

### In plain English

Attacks here are less common, but the consequences are bigger. A joint US government advisory warns of active attacks on internet-exposed Siemens PLCs, which are used in vessel automation. Thousands of Dahua cameras have been taken over. Wartsila and Furuno equipment has weaknesses with no simple fix.

### What to do

- Ask your onboard technical person to confirm no bridge, automation or camera system is reachable from the internet.
- Check whether you have Furuno FA-50 AIS, Wartsila FOS-Onboard or Dahua cameras.
- Keep these systems on their own network, away from crew and guest devices.
- Contact IT support if unsure.

\+Technical detail for your onboard technical person Tap to open / close ▾

| Reference | Issue | Date | Status |
| --- | --- | --- | --- |
| AA26-231A | Joint NSA, CISA, FBI, DOE and EPA advisory on internet-exposed Siemens S7 PLCs used in vessel automation. | 19 Aug | Active threat, exploited. |
| CVE-2021-33044 CVE-2021-33045 | Mass compromise of internet-exposed Dahua and EZ-IP cameras via legacy authentication bypass and P2P cloud relay. More than 14,500 devices per third-party telemetry. | 18 Aug | Exploited. |
| CVE-2026-78225 CVE-2026-81855 | Wartsila FOS-Onboard hardcoded cryptographic keys allow malicious firmware pushes. | 15 Sep | No known exploitation. |
| CVE-2026-59769 CVE-2026-67578 | Furuno FA-50 Class B AIS transponder hard-coded credentials and missing authentication. End of life. | 26 Aug | No fix. No exploitation reported. |
| CVE-2026-68070 and others | Digital Watchdog VMAX DVR and NVR unauthenticated root code execution. | 15 Sep | Check vendor advisory. |

**Actions:** inventory the bridge and OT network, confirm segmentation from crew and guest networks, and scan for exposed S7 and camera services. Where there is no fix, isolate the device and plan its replacement.

### How we rate items

**Exploited.** The vendor or CISA's Known Exploited Vulnerabilities list confirms attacks in the wild.

**Critical.** The vendor or CVSS rates it critical. This says nothing about whether attacks are happening.

**Watch.** No confirmed attacks, but the item is on kit that matters, or no fix exists.

**Sources.** Vendor security advisories, CISA Known Exploited Vulnerabilities catalogue and CISA advisories. Where a third-party report disagrees with the vendor, we follow the vendor. This briefing is a snapshot as of 7 October 2026. Fix status can change, so check vendor pages before acting.

[**Click here to join our Cybersecurity Threat Intelligence WhatsApp Group for Superyacht Crew - CyIntel.**](https://chat.whatsapp.com/HYSx9cqcLqPF42iftYw2zt?mode=gi_t)

---

Welcome to our bi-weekly cyber briefing for superyacht crew, where I share some of the major developments, lessons learned and helpful guides to help you improve onboard cybersecurity. Make sure to [**follow my LinkedIn page**](https://www.linkedin.com/in/superyachtcybersecurity/) and [**Anchorpoint's LinkedIn page**](https://www.linkedin.com/company/trustanchorpoint/) to receive updates on the future of superyacht cybersecurity!

To receive these and other curated updates to your inbox on a regular basis, please sign up for our email [**by clicking here**](https://2f009r.share-eu1.hsforms.com/2vmZv2EFcTRq5KwDy93Wwzw).

## Share this post

<https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ftrustanchorpoint.com%2Finsights%2Fsuperyacht-cyintel-briefing-7-october-2026><https://twitter.com/intent/tweet?url=https%3A%2F%2Ftrustanchorpoint.com%2Finsights%2Fsuperyacht-cyintel-briefing-7-october-2026><https://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Ftrustanchorpoint.com%2Finsights%2Fsuperyacht-cyintel-briefing-7-october-2026><https://pinterest.com/pin/create/button/?url=https%3A%2F%2Ftrustanchorpoint.com%2Finsights%2Fsuperyacht-cyintel-briefing-7-october-2026>[mailto:https%3A%2F%2Ftrustanchorpoint.com%2Finsights%2Fsuperyacht-cyintel-briefing-7-october-2026](mailto:https%3A%2F%2Ftrustanchorpoint.com%2Finsights%2Fsuperyacht-cyintel-briefing-7-october-2026)

## Keep reading

### [![inspection of superyacht cybersecurity](https://trustanchorpoint.com/hs-fs/hubfs/AI-Generated%20Media/Images/anime%20A%20new%20build%20yacht%20being%20inspected%20for%20cybersecurity%20controls%20in%20the%20rack%20space%20with%20just%20one%20person%20with%20two%20arms%20looking%20closely%20at%20the%20configu.png?width=1536&height=1024&name=anime%20A%20new%20build%20yacht%20being%20inspected%20for%20cybersecurity%20controls%20in%20the%20rack%20space%20with%20just%20one%20person%20with%20two%20arms%20looking%20closely%20at%20the%20configu.png) Cybersecurity superyacht new build IACS UR E26 & E27: Cybersecurity Regulations for Superyachts](https://trustanchorpoint.com/insights/iacs-ur-e26-e27-cybersecurity-regulations-for-superyachts)

### [![](https://trustanchorpoint.com/hs-fs/hubfs/Newsletter%20Header_large_nologo.png?width=1920&height=1080&name=Newsletter%20Header_large_nologo.png) Cybersecurity Yachting superyacht If Password Managers Aren’t Perfect, Are They Still Worth It?](https://trustanchorpoint.com/insights/if-password-managers-arent-perfect-are-they-still-worth-it)

[![L-White-White-Tran](https://trustanchorpoint.com/hs-fs/hubfs/L-White-White-Tran.png?width=200&height=56&name=L-White-White-Tran.png "L-White-White-Tran")](https://www.trustanchorpoint.com)

<https://wa.me/+447493651484><https://www.youtube.com/@trustanchorpoint><https://www.linkedin.com/company/trustanchorpoint/><https://www.facebook.com/trustanchorpoint><https://www.instagram.com/trustanchorpoint><https://www.tiktok.com/@trustanchorpoint?is_from_webapp=1&sender_device=pc><https://x.com/yachtcyberguy>

- [Privacy Policy](https://trustanchorpoint.com/hubfs/Privacy%20Policy.pdf)
- [Terms & Conditions](https://trustanchorpoint.com/hubfs/Terms%20and%20Conditions.pdf)
- [Contact Us](https://trustanchorpoint.com/contact)
- [Climate Pledge](https://climate.stripe.com/hLNMmV)

© 2026 Anchorpoint (trading name of Anchorpoint Cyber Limited). Company number 16320713, registered in England. All rights reserved.

<iframe style="border: 0; margin: 0px auto; display: block;" xml="lang" src="https://climate.stripe.com/badge/b1xAMU?theme=light&amp;size=small&amp;locale=en-GB" width="380" height="38"></iframe>

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Matt",
    "url" : "https://trustanchorpoint.com/insights/author/matt"
  },
  "dateModified" : "2026-10-07T13:03:40.513Z",
  "datePublished" : "2026-10-07T11:00:36.000Z",
  "headline" : "Superyacht Cyber Intelligence: Onboard Firewall Flaws Under Attack (Issue #018)",
  "image" : [ "https://trustanchorpoint.com/hubfs/Cover.png" ],
  "mainEntityOfPage" : {
    "@id" : "https://trustanchorpoint.com/insights/superyacht-cyintel-briefing-7-october-2026",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://trustanchorpoint.com/hubfs/Black-White.png"
    },
    "name" : "Anchorpoint Cyber Limited"
  }
}
```