Scworld
Critical PHP Object Injection Vulnerability in Mirasvit Cache Warmer
Article Content
A critical vulnerability, CVE-2026-45247, has been identified in the Mirasvit Full Page Cache Warmer for Magento 2, allowing unauthenticated remote code execution via a crafted CacheWarmer cookie. The flaw, rated 9.8 on the CVSS scale, affects versions prior to 1.11.12 and is due to unsafe deserialization of attacker-controlled data. Mirasvit released a patch on May 25, 2026, and users are urged to update immediately as the vulnerability is actively exploited. Security teams are advised to monitor for exploitation attempts, which can be identified by specific request signatures. The vulnerability highlights the importance of patch management and proactive security measures in e-commerce environments.
Key Points: • CVE-2026-45247 allows unauthenticated remote code execution via a crafted cookie. • The vulnerability affects Mirasvit Full Page Cache Warmer for Magento 2 versions before 1.11.12. • Mirasvit released a patch on May 25, 2026, and users are urged to update immediately.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.