Join our Experts on June 24 as they explain how to Detect, Divert, and Deceive AI-Assisted Threats

CVE-2026-48027

CVE-2026-48027 is a critical supply-chain flaw in Nx Console v18.95.0 that steals developer credentials. Upgrade to v18.100.0 immediately.

CVSS Gauge
CVSS Needle

Summary

CVE-2026-48027 is a critical supply chain security incident affecting Nx Console version 18.95.0. A malicious build of the extension was briefly published to the Visual Studio Marketplace and OpenVSX on May 19, 2026, before being removed. The compromised release contained embedded malicious code capable of collecting credentials, tokens, and other sensitive information from developer systems and transmitting the data externally. The issue is limited to version 18.95.0, while version 18.100.0 and later releases are not affected.

Due to confirmed exploitation in the wild and the potential exposure of development environments, organizations should take immediate remediation measures.

Urgent Actions Required

Which Systems Are Vulnerable to CVE-2026-48027?

Technical Overview

How Does the CVE-2026-48027 Exploit Work?

The attack typically follows these steps:

CVE-2026-48027

What Causes CVE-2026-48027?

Vulnerability Root Cause:

CVE-2026-48027 originated from a compromised release of the Nx Console extension. A malicious version, 18.95.0, was published to official extension marketplaces and contained embedded malicious code. When installed and activated, the compromised extension could collect credentials, tokens, and other sensitive information from affected developer systems.

The issue is classified as CWE-506: Embedded Malicious Code, reflecting the inclusion of unauthorized functionality within a trusted software component.

How Can You Mitigate CVE-2026-48027?

If immediate patching is delayed or not possible:

  • Identify and remove Nx Console version 18.95.0 from affected systems.
  • Review vendor-provided indicators of compromise (IOCs) to determine whether the malicious release was installed.
  • Check systems for known persistence artifacts and suspicious processes associated with the compromise.
  • Rotate credentials, tokens, secrets, and SSH keys that may have been accessible from affected machines.
  • Inspect source code repositories, development assets, and build outputs for signs of unauthorized access or data exposure.

Which Assets and Systems Are at Risk?

Will Patching CVE-2026-48027 Cause Downtime?

Patch application impact: Low. Upgrade Nx Console to version 18.100.0 or later and remove version 18.95.0. Review affected systems for indicators of compromise.

Mitigation (if immediate patching is not possible): Remove version 18.95.0, check for indicators of compromise, delete persistence artifacts, and rotate exposed credentials and secrets.

How Can You Detect CVE-2026-48027 Exploitation?

Indicators of Compromise (IOCs/IOAs):

Behavioral Indicators:

Remediation & Response

See More. Detect Faster. Respond Smarter with Fidelis NDR

      • Full visibility across network traffic and encrypted communications
      • Automated threat detection, hunting, and malware analysis
      • Integrated DLP, forensics, sandboxing, and threat intelligence
Download the Data Sheet

CVSS Breakdown Table

MetricValue Description
Base Score9.8Critical vulnerability with significant impact on affected systems.
Attack VectorNetwork The compromised extension was distributed through online extension marketplaces.
Attack ComplexityLowExploitation does not require complex conditions.
Privileges RequiredNoneNo privileges are required to obtain the compromised extension.
User Interaction NoneCVSS scoring assigns no user interaction requirement.
Scope Unchanged Impact remains within the affected component.
Confidentiality Impact HighSensitive credentials, tokens, and secrets may be exposed.
Integrity Impact HighMalicious code can affect the integrity of the development environment.
Availability ImpactHighThe compromised extension can adversely affect systems.

Related Readings

One Platform for All Adversaries

See Fidelis in action. Learn how our fast and scalable platforms provide full visibility, deep insights, and rapid response to help security teams across the World protect, detect, respond, and neutralize advanced cyber adversaries.