Scworld
Critical PHP Object Injection Vulnerability in Mirasvit Cache Warmer
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A critical vulnerability, CVE-2026-45247, has been identified in the Mirasvit Full Page Cache Warmer for Magento 2, allowing unauthenticated remote code execution via a crafted CacheWarmer cookie. The flaw, rated 9.8 on the CVSS scale, affects versions prior to 1.11.12 and is due to unsafe deserialization of attacker-controlled data. Mirasvit released a patch on May 25, 2026, and users are urged to update immediately as the vulnerability is actively exploited. Security teams are advised to monitor for exploitation attempts, which can be identified by specific request signatures. The vulnerability highlights the importance of patch management and proactive security measures in e-commerce environments.
Key Points: • CVE-2026-45247 allows unauthenticated remote code execution via a crafted cookie. • The vulnerability affects Mirasvit Full Page Cache Warmer for Magento 2 versions before 1.11.12. • Mirasvit released a patch on May 25, 2026, and users are urged to update immediately.