<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=10643465&amp;fmt=gif">

CISA Warns of Actively Exploited Magento Plugin Flaw Enabling Remote Code Execution

Urgent patch needed for Mirasvit vulnerability in Magento 2. CVE-2026-45247 allows remote code execution, posing a high risk to stores.
Content Team

CISA added a critical vulnerability in the Mirasvit Full Page Cache Warmer extension for Magento 2 to its Known Exploited Vulnerabilities catalog on 3 June, giving federal agencies until 6 June to patch. The flaw, CVE-2026-45247, carries a near-perfect CVSS score of 9.8 and requires no authentication to exploit.

Attackers inject malicious PHP objects through the CacheWarmer cookie, which deserializes them without class restrictions and escalates to full remote code execution on Magento and Adobe Commerce servers. Imperva reports active exploitation began shortly after public disclosure on May 26.

Thousands of stores are at risk — any running a version before 1.11.12 should update immediately. Given exploitation started over a week ago, also check your logs for CacheWarmer cookies carrying base64-encoded serialized objects, which typically begin with "Tz," "Qz" or "YT."

Source: SecurityWeek

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo