CVE-2026-48027: Nx Nx Console
EPSS1.3%No. 1646 of 1739 in KEV
CVE year2026listed the same year
Same vendor in KEV1
Same product1
| Field | Value |
|---|---|
| Vendor | Nx |
| Product | Nx Console |
| Name | Nx Console Embedded Malicious Code Vulnerability |
| Added to KEV | 2026-05-27 |
| US federal due date | 2026-06-10 |
| Ransomware use | Known |
| CWE | CWE-506 |
CISA description
Nx Console contains an embedded malicious code vulnerability that allowed a malicious version of Nx Console to be published. The compromised extension fetched an obfuscated payload that could harvested credentials from multiple sources on disk and in memory.
Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page
A Nx Nx Console vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2026-05-27.