Critical PHP Object Injection Vulnerability in Mirasvit Cache Warmer

Critical PHP Object Injection Vulnerability in Mirasvit Cache Warmer

First seen 4 Jun 2026, 21:12 UTC Scworldsansec.ionvd.nist.govDarknetsearchCsa.Sg+3 84% similarity 72.9

Article Content

Browse articles
ThreatCluster

A critical vulnerability, CVE-2026-45247, has been identified in the Mirasvit Full Page Cache Warmer for Magento 2, allowing unauthenticated remote code execution via a crafted CacheWarmer cookie. The flaw, rated 9.8 on the CVSS scale, affects versions prior to 1.11.12 and is due to unsafe deserialization of attacker-controlled data. Mirasvit released a patch on May 25, 2026, and users are urged to update immediately as the vulnerability is actively exploited. Security teams are advised to monitor for exploitation attempts, which can be identified by specific request signatures. The vulnerability highlights the importance of patch management and proactive security measures in e-commerce environments.

Key Points: • CVE-2026-45247 allows unauthenticated remote code execution via a crafted cookie. • The vulnerability affects Mirasvit Full Page Cache Warmer for Magento 2 versions before 1.11.12. • Mirasvit released a patch on May 25, 2026, and users are urged to update immediately.

ThreatCluster AI

Timeline

2026-05-26
CVE-2026-45247 published
Mirasvit disclosed a critical PHP object injection vulnerability affecting their Cache Warmer extension.
nvd.nist.gov
2026-06-03
CVE added to CISA KEV
CVE-2026-45247 was added to the Known Exploited Vulnerabilities Catalog due to active exploitation.
Darknetsearch
2026-06-04
First public PoC released
A proof of concept for exploiting CVE-2026-45247 was made public, increasing the risk of attacks.
sansec.io
2026-06-05
Security update recommended
Mirasvit urged all users to update to version 1.11.12 to mitigate the critical vulnerability.
Csa.Sg

Community

Browse all →