logo

CISA flags data-theft bug in NSA-built OT networking tool

ID: 2981251a-4111-5577-af48-0fa355f24333

STIX ID: report--2981251a-4111-5577-af48-0fa355f24333

Feed Name: The Register (Security)

Threat Score
30/100

Date Published: 2026-04-29

Date Updated: 2026-04-29

Author: Connor Jones

...
...

CISA warned that GrassMarlin (an NSA open-source tool) contains an XXE vulnerability (CVE-2026-6807) that can disclose sensitive data; the project went EOL in 2017 so no patch is forthcoming. A Rapid7 researcher published a public proof-of-concept showing out-of-band exfiltration is possible by crafting malicious session XML files, though exploitation is constrained by required Java versions, error conditions, and realistic delivery via phishing. CISA recommends isolating control systems from the internet and securing remote access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.