Theregister CISA Warns of Data-Theft Vulnerability in NSA's GrassMarlin Tool
Article Content
- •CISA warns of CVE-2026-6807 affecting all versions of GrassMarlin.
- •GrassMarlin is an NSA-developed tool that has been EOL since 2017.
- •Exploitation is possible through XML External Entity (XXE) attacks, primarily via phishing.
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding a vulnerability in GrassMarlin, a tool developed by the NSA, which could allow attackers to access sensitive information. This vulnerability, identified as CVE-2026-6807, affects all versions of GrassMarlin, which was open-sourced for network security in critical infrastructure. The flaw, stemming from insufficient hardening of the XML parsing process, can lead to data exfiltration through XML External Entity (XXE) attacks. GrassMarlin has been end-of-life (EOL) since 2017, meaning no fixes are forthcoming. CISA advises users to secure their control systems and networks against potential exploitation. A proof-of-concept exploit has been developed and shared publicly, indicating the vulnerability can be exploited primarily via phishing attacks. While the threat is significant, it is noted that the bug may not pose a major risk to most organizations.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track CVE-2026-6807 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Sets Oct. 11 Deadline for Patching Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog after they were exploited by the China-linked group Flax Typhoon. Federal agencies must patch or retire the affected software by October 11, 2026. The vulnerabilities…