A compromised version of the Nx Console VS Code extension contained embedded malicious code. This is a supply chain attack targeting developer workstations, not internet-facing servers.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: USER_INTERACTION
CVE Published: 2026-05-27
Added to CISA KEV: 2026-05-27 0 DAY BETWEEN CVE AND KEV
CVE-2026-48027 is a critical vulnerability involving embedded malicious code within the Nx Console extension for Visual Studio Code [1]. It was officially added to the CISA Known Exploited Vulnerabilities (KEV) Catalog on May 27, 2026, due to evidence of active exploitation in the wild [2] [4].
| Feature | Status/Description |
|---|---|
| CISA KEV Status | Included (Added May 27, 2026) [2] |
| Active Exploitation | Yes, confirmed in the wild [2] |
| Affected Software | Nx Console extension for Visual Studio Code (specifically version 18.95.0) [1] |
| Internet-Facing | No (Client-side/Developer environment) [1] |
Any developer who installed or updated to Nx Console version 18.95.0 during the compromised window can have their system compromised; the malicious extension executes arbitrary code with the permissions of the Visual Studio Code process, potentially allowing access to source code, credentials, and e…
CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
CVE-2026-48027. Nx Console Embedded Malicious Code Vulnerability: Nx Console contains an embedded malicious code vulnerability that allowed a malicious version ... ... For the benefit of the cybersecurity community and network defenders—and to help every organization better manage vulnerabilities an…
This CVE is in CISA's Known Exploited Vulnerabilities Catalog ; Nx Console Embedded Malicious Code Vulnerability, 05/27/2026, 06/10/2026 ... ... NVD MENU Information Technology Laboratory National Vulnerability Database Vulnerabilities…