logo

CISA flags data-theft bug in NSA-built OT networking tool

ID: 84fa63a3-7168-56dd-bf50-95898b19984a

STIX ID: report--84fa63a3-7168-56dd-bf50-95898b19984a

Feed Name: The Register (Security)

Threat Score
35/100

Date Published: 2026-04-29

Date Updated: 2026-05-06

...
...

CISA has flagged CVE-2026-6807, an XXE (CWE-611) vulnerability in the NSA open-source tool GrassMarlin that can disclose sensitive information when crafted XML session files are parsed. GrassMarlin is end-of-life (2017) with no fix; a public proof-of-concept shows out-of-band exfiltration is possible but practical exploitation requires phishing delivery and specific Java/runtime conditions, so risk is limited to targeted social-engineering scenarios.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.