logo

CVE-2026-45247: Critical Magento RCE Vulnerability in Mirasvit Cache Warmer

ID: 806b0b74-e40a-542e-ad04-0ea633584779

STIX ID: report--806b0b74-e40a-542e-ad04-0ea633584779

Feed Name: Security Boulevard

Threat Score
90/100

Date Published: 2026-06-09

Date Updated: 2026-06-09

Author: Deepak Kumar Choudhary

...
...

**Executive Summary:** CVE-2026-45247 is a critical (CVSS 9.8) PHP object injection vulnerability in the Mirasvit Full Page Cache Warmer extension for Magento/Adobe Commerce that allows unauthenticated remote code execution via unsafe unserialize() of a CacheWarmer cookie; it is actively exploited and listed in CISA's KEV catalog, so affected installations should immediately upgrade to version 1.11.12 or disable the extension and perform compromise assessments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.