Fixing and finding
Jump to remediation plan
CVE ID

CVE-2026-48027

Published 2026-05-27
Updated 3 months ago
Vendor/s
Nx
Product/s
Nx Console
Version/s
18.95.0
KEV Status
Active Exploitation
Listed in CISA's Known Exploited Vulnerabilities catalog. Active exploitation observed in the wild.
CVSS Score (v3.1)
9.8
/ 10
Critical
Severity Details
Base score
9.8 Critical
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Description

Critical CVSS 9.8 supply chain vulnerability in Nx Console 18.95.0. Malicious code was published to VS Marketplace. Upgrade to 18.100.0 immediately.

CPE

Nx logo
Nx
Product Version Start Version End (excl.) Status
nx_console 18.95.0 18.95.0 vulnerable

Related weakness (CWE)

CWE-506

Remediation plan

1

Apply official patches

Immediately upgrade Nx Console to version 18.100.0 or later, which has been verified by the vendor as safe and free of the malicious code introduced in the compromised 18.95.0 release.

2

Update affected systems

Identify and purge Nx Console version 18.95.0 from all developer workstations and CI/CD pipelines. Ensure that any cached extension files in local directories (e.g., .vscode/extensions) are manually deleted if the automatic update fails.

3

Restrict access

Implement strict extension management policies within IDEs to prevent the installation of unverified or compromised packages. Consider using a private extension gallery or requiring administrative approval for new extension versions in high-security environments.

4

Monitor for exploitation

Perform a forensic audit of any system that had version 18.95.0 installed. Search for indicators of compromise such as unauthorized outbound network connections, unexpected child processes spawned by the IDE, or evidence of credential dumping.

Detection Guidance

"Detection should focus on identifying the specific malicious version (18.95.0) within extension metadata files on developer machines. Security teams should monitor EDR logs for suspicious shell activity or network connections originating from the IDE process (e.g., Code.exe) to unknown external IP addresses. Additionally, check for unusual file modifications in sensitive directories or the creation of new, unauthorized local user accounts that may have occurred during the window of exposure on May 19, 2026."

References

Sources

NIST National Vulnerability Database (NVD)
CISA Known Exploited Vulnerabilities (KEV)

Experience superior visibility and a simpler approach to cyber risk management