CVE•Published 2026-05-27•Modified 2026-05-27•1 article on news•6 live references•NVD data
CVE-2026-48027Nx · Nx_console
Vulnerability data via NVD (ingested)
CVSS v3.1
9.8
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS percentile
—
Weaknesses (CWE)
Description
Nx Console is the user interface for Nx & Lerna. On 19 May 2026, a malicious version of Nx Console, 18.95.0, was published at 12:30 PM UTC and removed soon after at 12:48 PM UTC, leaving it available for ~18 minutes in Visual Studio Marketplace. For OpenVSX, the problem was detected later, and the compromised version was available from 12:33 UTC to 13:09 UTC (~36 minutes). Version 18.100.0 of Nx Console is not compromised and users may remediate by upgrading to that version.
Timeline
Published 2026-05-27
Modified 2026-05-27
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
Shodan · vuln tag0 hosts
vuln:CVE-2026-48027Hosts Shodan has explicitly fingerprinted as vulnerable.
Shodan · product + version
product:"Nx Nx Console" version:"18.95.0"Version-pinned fingerprint from NVD's first vulnerable CPE.
Shodan · banner/body mention
http.html:"Nx Console"HTTP body or banner mentions "Nx Console" — catches deploys Shodan didn't identify as a product.
More intel sources (5)
Shodan report
vuln:CVE-2026-48027Country / ASN / product breakdown for the vuln query.
Censys
vulnerabilities.cve_id: CVE-2026-48027Censys host search filtered to this CVE id.
grep.app
CVE-2026-48027Public source-code mentions — fast PoC discovery.
GitHub code
CVE-2026-48027GitHub code search for direct mentions.
Google dork
"CVE-2026-48027" exploit -site:nvd.nist.govWrite-ups and news, NVD excluded.
Known PoCs on GitHub (3)
CVE-2026-480273 repos
lateos-ai/npm-scanJavaScript
Modern supply chain security for the npm ecosystem. Static + behavioral analysis that catches what npm audit, Snyk, and Socket miss — obfuscated payloads, credential stealers, cond…
barmi/cve-patch-auditorGo
Audit CVE impact, patch status, remediation progress, and verification results across systems.
DevGreick/devgreickPython