Skip to content
COOEY

EXPOSURES › CVE-2026-48027

CVE-2026-48027

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2026-05-27 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-48027 ↗
⌖ EXPLOITED IN THE WILD SHAME 85/100 ransomwareexploited-in-wildsupply-chaindata-breach

Nx Console extension published a malicious version that harvested credentials from disk and memory.

A compromised Nx Console extension distributed an obfuscated payload capable of harvesting credentials from disk and memory, directly enabling credential theft and ransomware-like behavior. This supply-chain failure exposes DIB organizations to unauthorized access and data exfiltration if they deploy the vulnerable extension, violating FedRAMP requirements for secure software supply chains.

Shame score — Publishing a malicious extension that actively harvested credentials represents a severe supply-chain failure with no prior disclosure or patching.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Nx Console contains an embedded malicious code vulnerability that allowed a malicious version of Nx Console to be published. The compromised extension fetched an obfuscated payload that could harvested credentials from multiple sources on disk and in memory.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.