CVE-2022-42948: Fortra Cobalt Strike User Interface Remote Code Execution Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2023-03-30. EPSS: 2.7% chance of exploitation in the next 30 days.

Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components. By injecting crafted HTML code, it is possible to remotely execute code in the Cobalt Strike UI.

Affected products

Published 2023-03-24. Last modified 2026-06-17.