CISA issued an advisory for FURUNO FA-50 Class B AIS Transponder affecting all versions, with two critical/high vulnerabilities. CVE-2026-59769 involves Use of Hard-coded Credentials (CVSS 9.1), allowing attackers with credential knowledge and in-vessel network access to alter device settings. CVE-2026-67578 involves Missing Authentication for Critical Function (CVSS 7.5), enabling configuration changes without authentication. Production of the FA-50 ended in October 2020 and no software patches will be provided. Mitigations include isolating devices from the internet, physically securing vessels, and using VPNs for remote access. The vulnerabilities affect the Transportation Systems critical infrastructure sector and are deployed worldwide. Souvik Kandar reported the vulnerabilities, coordinated through JPCERT/CC and CISA. No known public exploitation has been reported at this time.