CISA issued an advisory for CVE-2026-6807, an XML External Entity (XXE) vulnerability in the NSA-developed OT and ICS network-mapping tool GrassMarlin. The flaw, tracked as CWE-611 and scored CVSS 5.5, stems from insufficient hardening of XML parsing when the application processes crafted session data, potentially allowing disclosure of sensitive information. GrassMarlin is used in critical infrastructure, industrial control systems, SCADA, and broader IT environments, and CISA said the product is deployed worldwide.
Reporting on the advisory said the issue affects all versions, including version 3.2.1, and that no patch is expected because GrassMarlin reached end-of-life in 2017. Session data is stored in XML files packaged inside .gm3 archives, and a public proof-of-concept from Rapid7 researcher Anna Quinn demonstrated out-of-band exfiltration of arbitrary files through malicious XML content, though practical delivery appears to rely largely on phishing and the bundled Java environment. CISA said it has no evidence of public exploitation targeting this flaw and urged operators to minimize internet exposure, isolate control networks behind firewalls, separate them from business networks, and secure remote access with updated VPNs.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
Rapid7 penetration tester Anna Quinn published a public proof-of-concept demonstrating out-of-band exfiltration of arbitrary files from GrassMarlin via malicious XML content. The technique exploited insufficient hardening of XML parsing in session data handling, though practical delivery was described as constrained and likely reliant on phishing.
Because GrassMarlin is no longer maintained, CISA recommended defensive mitigations including minimizing network exposure, isolating control systems behind firewalls, separating them from business networks, and using secure updated VPNs for remote access. The guidance was aimed at organizations using the tool in critical infrastructure, ICS, and SCADA environments.
CISA published advisory ICSA-26-118-01 for CVE-2026-6807, an XML External Entity vulnerability affecting GrassMarlin 3.2.1, with the Register noting all versions are affected. CISA said successful exploitation could disclose sensitive information, assigned a CVSS v3.1 score of 5.5, and reported no known public exploitation targeting the flaw.
The NSA-developed GrassMarlin OT network mapping tool reached end-of-life in 2017, meaning the newly reported vulnerability will not receive a vendor patch. This status shaped later mitigation guidance, which focused on defensive measures rather than remediation through an update.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
5 references tracked. Mallory keeps watching after this page renders.
go.theregister.com
Open sourcetheregister.com
Open sourcecisa.gov
Open sourcegithub.com
Open sourcesdxcentral.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.