logo

CISA Warns of critical Magento Cache Warmer RCE flaw Exploited in Attacks

ID: 537f21a2-defe-549c-922b-cff8e7ddb0b0

STIX ID: report--537f21a2-defe-549c-922b-cff8e7ddb0b0

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2026-06-04

Date Updated: 2026-06-04

Author: Abinaya

...
...

CISA has issued an urgent warning about CVE-2026-45247, an insecure deserialization vulnerability in the Mirasvit Full Page Cache Warmer Magento extension that allows unauthenticated attackers to send malicious serialized PHP objects via a CacheWarmer cookie to achieve remote code execution; the flaw is actively exploited in the wild, was added to CISA's KEV catalog, and federal remediation was mandated. Organizations are advised to apply vendor patches or remove the extension, use WAF rules, monitor logs for manipulated CacheWarmer cookies and unexpected processes or files, and restrict access to sensitive endpoints.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.