logo

Cache Warmer RCE Flaw Patched in Magento Extension

ID: 35b8c081-f64f-510b-a4cd-7474d57d2726

STIX ID: report--35b8c081-f64f-510b-a4cd-7474d57d2726

Feed Name: securityonline.info

Threat Score
88/100

Date Published: 2026-06-01

Date Updated: 2026-06-01

Author: Ddos

...
...

A critical unauthenticated RCE (CVE-2026-45247) in a popular full-page Cache Warmer extension for Magento/Adobe Commerce allows attackers to supply crafted cookies that reach PHP's native unserialize(), causing Magento PHP object injection; researchers report roughly 6,000 compromised stores. Immediate remediation is to upgrade the extension to version 1.11.12 and monitor server traffic for base64-encoded serialized PHP object markers beginning with Tz, Qz, or YT.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.