CISA flags data-theft bug in NSA-built OT networking tool
ID: 2981251a-4111-5577-af48-0fa355f24333
STIX ID: report--2981251a-4111-5577-af48-0fa355f24333
Feed Name: The Register (Security)
CISA warned that GrassMarlin (an NSA open-source tool) contains an XXE vulnerability (CVE-2026-6807) that can disclose sensitive data; the project went EOL in 2017 so no patch is forthcoming. A Rapid7 researcher published a public proof-of-concept showing out-of-band exfiltration is possible by crafting malicious session XML files, though exploitation is constrained by required Java versions, error conditions, and realistic delivery via phishing. CISA recommends isolating control systems from the internet and securing remote access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
