NSA GRASSMARLIN XML External Entity Vulnerability Advisory
⚠️ A vulnerability in NSA GRASSMARLIN allows crafted session data to trigger improper XML parsing that may disclose sensitive information. Tracked as CVE-2026-6807 and classified under CWE-611, the issue affects GRASSMARLIN v3.2.1 and carries a CVSS 3.1 base score of 5.5 (MEDIUM). The GRASSMARLIN project reached end-of-life in 2017 and is archived, so no vendor patches are planned; CISA recommends compensating controls, network isolation, and following published ICS defensive guidance.
