securityaffairs.com 5/28/2026, 1:31:55 PM · external

CISA warns of Daemon Tools, TanStack and Nx Console flaws

CISA warns of Daemon Tools, TanStack and Nx Console flaws
CyberSIXT Evidence Panel
Primary Source cisa.gov
CISA KEV Listed in KEV
Patch Patch Available

THE U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three new vulnerabilities to its Known Exploited Vulnerabilities catalog: 1) CVE-2026-8398 - Daemon Tools Lite, a supply chain attack affecting downloaded installers; 2) CVE-2026-45321 - TanStack npm packages, involving credential-stealing malware in malicious package versions; and 3) CVE-2026-48027 - Nx Console, where a malicious extension was briefly available in marketplaces.

CISA requires federal agencies to address these vulnerabilities by June 10, 2026, and recommends that private organizations review the catalog to mitigate risks.

View Primary Source Via securityaffairs.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline