Skip to content
CISA Warns of Data-Theft Vulnerability in NSA's GrassMarlin Tool

CISA Warns of Data-Theft Vulnerability in NSA's GrassMarlin Tool

First seen 29 Apr 2026, 17:06 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •April 30, 2026 at 17:03 UTC
  • •CISA warns of CVE-2026-6807 affecting all versions of GrassMarlin.
  • •GrassMarlin is an NSA-developed tool that has been EOL since 2017.
  • •Exploitation is possible through XML External Entity (XXE) attacks, primarily via phishing.

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding a vulnerability in GrassMarlin, a tool developed by the NSA, which could allow attackers to access sensitive information. This vulnerability, identified as CVE-2026-6807, affects all versions of GrassMarlin, which was open-sourced for network security in critical infrastructure. The flaw, stemming from insufficient hardening of the XML parsing process, can lead to data exfiltration through XML External Entity (XXE) attacks. GrassMarlin has been end-of-life (EOL) since 2017, meaning no fixes are forthcoming. CISA advises users to secure their control systems and networks against potential exploitation. A proof-of-concept exploit has been developed and shared publicly, indicating the vulnerability can be exploited primarily via phishing attacks. While the threat is significant, it is noted that the bug may not pose a major risk to most organizations.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 162d ago How this analysis works

Timeline

2026-04-28
CVE-2026-6807 published
2026-04-29
First public proof-of-concept exploit released

More articles in this cluster (3)

Following this threat?

Track CVE-2026-6807 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed