🟢 CVE-2026-48027

A compromised version of the Nx Console VS Code extension contained embedded malicious code. This is a supply chain attack targeting developer workstations, not internet-facing servers.

← Back to Overview
LOW_RISK
Risk Level
9.3
CVSS Score
NETWORK
Attack Vector
Persistence
ATT&CK Tactic
T1176 — Software Extensions
ATT&CK Technique
VERY_LOW
Deployment Risk
Yes (+1d)
Ransomware

📋 Vulnerability Details

Data Source: CIRCL

Confidence: HIGH

Exploitation Method: USER_INTERACTION

CVE Published: 2026-05-27

Added to CISA KEV: 2026-05-27 0 DAY BETWEEN CVE AND KEV

🎯 Recommendations:

🔍 Web Intelligence (Kagi · 2026-05-28)

CVE-2026-48027 is a critical vulnerability involving embedded malicious code within the Nx Console extension for Visual Studio Code [1]. It was officially added to the CISA Known Exploited Vulnerabilities (KEV) Catalog on May 27, 2026, due to evidence of active exploitation in the wild [2] [4].

Key Details
FeatureStatus/Description
CISA KEV StatusIncluded (Added May 27, 2026) [2]
Active ExploitationYes, confirmed in the wild [2]
Affected SoftwareNx Console extension for Visual Studio Code (specifically version 18.95.0) [1]
Internet-FacingNo (Client-side/Developer environment) [1]
Exploitation and Technical Details
  • Attack Vector: The vulnerability is not an internet-facing service exploit in the traditional sense. Instead, it relies on developers installing or updating to the compromised version (18.95.0) of the Nx Console extension [1].
  • Exploitation Method: Once installed, the malicious extension executes arbitrary code with the same permissions as the Visual Studio Code process [1]. This allows attackers to potentially access sensitive information on the developer's machine, including source code, credentials, and environment variables [1].
  • Targeted Attacks: While the vulnerability is confirmed to be exploited in the wild, it is primarily categorized as a supply chain-style compromise affecting developer environments rather than a direct attack on internet-facing infrastructure [1]. Proof-of-concept material has been identified in security research contexts [1].
Organizations and individual developers are advised to review the official security advisory from the Nx Console project for remediation steps and to ensure they are not running the compromised version [3].

Sources

  1. CVE-2026-48027 - Exploits & Severity - Feedly

    Any developer who installed or updated to Nx Console version 18.95.0 during the compromised window can have their system compromised; the malicious extension executes arbitrary code with the permissions of the Visual Studio Code process, potentially allowing access to source code, credentials, and e…

  2. CISA Adds Three Known Exploited Vulnerabilities to Catalog

    CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.

  3. Known Exploited Vulnerabilities Catalog | CISA

    CVE-2026-48027. Nx Console Embedded Malicious Code Vulnerability: Nx Console contains an embedded malicious code vulnerability that allowed a malicious version ... ... For the benefit of the cybersecurity community and network defenders—and to help every organization better manage vulnerabilities an…

  4. CVE-2026-48027 Detail - NVD

    This CVE is in CISA's Known Exploited Vulnerabilities Catalog ; Nx Console Embedded Malicious Code Vulnerability, 05/27/2026, 06/10/2026 ... ... NVD MENU Information Technology Laboratory National Vulnerability Database Vulnerabilities…