CISA Warns of Actively Exploited Magento Plugin Flaw Enabling Remote Code Execution
Want more insights like this?
CISA added a critical vulnerability in the Mirasvit Full Page Cache Warmer extension for Magento 2 to its Known Exploited Vulnerabilities catalog on 3 June, giving federal agencies until 6 June to patch. The flaw, CVE-2026-45247, carries a near-perfect CVSS score of 9.8 and requires no authentication to exploit.
Attackers inject malicious PHP objects through the CacheWarmer cookie, which deserializes them without class restrictions and escalates to full remote code execution on Magento and Adobe Commerce servers. Imperva reports active exploitation began shortly after public disclosure on May 26.
Thousands of stores are at risk — any running a version before 1.11.12 should update immediately. Given exploitation started over a week ago, also check your logs for CacheWarmer cookies carrying base64-encoded serialized objects, which typically begin with "Tz," "Qz" or "YT."
Source: SecurityWeek