CVE-2026-45247: Critical Magento RCE Vulnerability in Mirasvit Cache Warmer
ID: 806b0b74-e40a-542e-ad04-0ea633584779
STIX ID: report--806b0b74-e40a-542e-ad04-0ea633584779
Feed Name: Security Boulevard
Threat Score
**Executive Summary:** CVE-2026-45247 is a critical (CVSS 9.8) PHP object injection vulnerability in the Mirasvit Full Page Cache Warmer extension for Magento/Adobe Commerce that allows unauthenticated remote code execution via unsafe unserialize() of a CacheWarmer cookie; it is actively exploited and listed in CISA's KEV catalog, so affected installations should immediately upgrade to version 1.11.12 or disable the extension and perform compromise assessments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
