Magento Security Alert: CISA Issues Warning on Exploited Flaw CVE-2026-45247 (2026)

The recent addition of a critical vulnerability impacting Mirasvit Cache Warmer, a popular Magento full-page cache extension, to the U.S. Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities (KEV) catalog is a significant development in the cybersecurity landscape. This vulnerability, tracked as CVE-2026-45247, carries a CVSS score of 9.8, indicating its high potential for remote code execution. The issue stems from the deserialization of untrusted data, allowing unauthenticated attackers to inject malicious PHP objects through the CacheWarmer cookie. This vulnerability affects all versions of the extension prior to version 1.11.12, with patches released on May 25, 2026. The severity of this flaw is underscored by the active exploitation observed by Sansec, which identified approximately 6,000 stores running Mirasvit extensions. Thales-owned Imperva has also reported active attack activity, with attackers using base64-encoded serialized objects to trigger PHP object deserialization and execute arbitrary commands on the underlying server. The targeted countries include the U.S., the U.K., France, and Australia, with gaming and business sites being the primary focus. The end goal of these attacks appears to be identifying vulnerable Magento environments and confirming remote code execution. In response to this threat, Federal Civilian Executive Branch (FCEB) agencies have been ordered to apply the necessary fixes by June 6, 2026. Site owners are advised to audit for storefront requests containing a CacheWarmer cookie with a value starting with 'CacheWarmer:', followed by a Base64-encoded string, as this is a strong indicator of an exploitation attempt. This incident highlights the ongoing challenges in cybersecurity, emphasizing the need for proactive measures to protect against emerging threats.

Magento Security Alert: CISA Issues Warning on Exploited Flaw CVE-2026-45247 (2026)
Top Articles
Latest Posts
Recommended Articles
Article information

Author: Nicola Considine CPA

Last Updated:

Views: 5599

Rating: 4.9 / 5 (69 voted)

Reviews: 92% of readers found this page helpful

Author information

Name: Nicola Considine CPA

Birthday: 1993-02-26

Address: 3809 Clinton Inlet, East Aleisha, UT 46318-2392

Phone: +2681424145499

Job: Government Technician

Hobby: Calligraphy, Lego building, Worldbuilding, Shooting, Bird watching, Shopping, Cooking

Introduction: My name is Nicola Considine CPA, I am a determined, witty, powerful, brainy, open, smiling, proud person who loves writing and wants to share my knowledge and understanding with you.