FAIL › dossier
Cobalt Strike
PRODUCT· dossier confidence 80%
Cobalt Strike is a red teaming tool with a documented history of critical remote code execution vulnerabilities in its UI and XSS components, which were exploited to allow remote attackers to execute arbitrary code.
PROFILE
CategoryproductWhat they doCobalt Strike is a penetration testing and red teaming tool used for adversary emulation and security assessments.
SECURITY POSTURE
The product has a documented history of critical remote code execution vulnerabilities in its user interface and cross-site scripting components, which were exploited to allow remote attackers to execute arbitrary code.
Notable failures
- CVE-2022-42948: UI RCE
- CVE-2022-39197: XSS RCE
Patterns: critical RCE vulnerabilities in core components
FAILURE HISTORY · 2
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2023-03-30 | CVE-2022-42948 | high | Fortra Cobalt Strike UI RCE |
| 2023-03-30 | CVE-2022-39197 | high | Fortra Cobalt Strike XSS allowed remote code execution |
DOSSIER SOURCES
Open questions: What is the current patch status for CVE-2022-42948 and CVE-2022-39197? · Are there any other known vulnerabilities in Cobalt Strike?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-12 04:01:33.449006+00:00