CVE-2026-45247Active Exploitation(mirasvit / full_page_cache_warmer)

CRITICALCVSS 9.3 · CRITICALCISA KEV

Exploitation observed; activity peaked at 25 mentions and remains active

Immediate actions

  • Patch mirasvit full_page_cache_warmer systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that allows unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the CacheWarmer cookie. Attackers can exploit the unrestricted call to PHP's native unserialize() function combined with gadget chains available in Magento and its dependencies to execute arbitrary code on the server.

8.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-06-06. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-502

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • full_page_cache_warmer

Threat summary

  • Active exploitation appears in 51 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 68 mentions across 19 observed days

What's happening

  • Active exploitation reported across 51 signals
  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 19 signals
  • Technical details provided in 56 signals
  • General: 5 classified signals
  • Peaked 12d ago at 25 mentions (2026-06-04); latest day: 1
  • 68 total mentions across 19 days

Affected systems

Vendors
Products
full_page_cache_warmer

Deep dive

Activity timeline68 mentions / 19d
06131925Mentions · 2026-05-26: 1Mentions · 2026-05-30: 1Mentions · 2026-05-31: 1Mentions · 2026-06-01: 2Mentions · 2026-06-02: 1Mentions · 2026-06-03: 3Mentions · 2026-06-04: 25Mentions · 2026-06-05: 6Mentions · 2026-06-06: 3Mentions · 2026-06-08: 5Mentions · 2026-06-09: 6Mentions · 2026-06-10: 6Mentions · 2026-06-18: 2Mentions · 2026-06-24: 1Mentions · 2026-06-25: 1Mentions · 2026-07-29: 1Mentions · 2026-08-07: 1Mentions · 2026-09-28: 1Mentions · 2026-10-07: 1PoC Mentioned / Linked · 2026-06-01: 1PoC Mentioned / Linked · 2026-06-04: 1PoC Mentioned / Linked · 2026-06-10: 1Exploit Tool / Code · 2026-06-08: 1Exploit Tool / Code · 2026-06-10: 1Active Exploitation · 2026-06-01: 1Active Exploitation · 2026-06-03: 2Active Exploitation · 2026-06-04: 24Active Exploitation · 2026-06-05: 5Active Exploitation · 2026-06-06: 2Active Exploitation · 2026-06-08: 5Active Exploitation · 2026-06-09: 5Active Exploitation · 2026-06-10: 4Active Exploitation · 2026-06-18: 1Active Exploitation · 2026-06-24: 1Active Exploitation · 2026-08-07: 1Patch / Workaround · 2026-05-26: 1Patch / Workaround · 2026-05-31: 1Patch / Workaround · 2026-06-02: 1Patch / Workaround · 2026-06-03: 1Patch / Workaround · 2026-06-04: 5Patch / Workaround · 2026-06-05: 5Patch / Workaround · 2026-06-09: 2Patch / Workaround · 2026-06-18: 1Patch / Workaround · 2026-06-25: 1Patch / Workaround · 2026-07-29: 1Technical Details · 2026-05-26: 1Technical Details · 2026-05-31: 1Technical Details · 2026-06-01: 2Technical Details · 2026-06-02: 1Technical Details · 2026-06-03: 2Technical Details · 2026-06-04: 25Technical Details · 2026-06-05: 5Technical Details · 2026-06-06: 2Technical Details · 2026-06-08: 5Technical Details · 2026-06-09: 6Technical Details · 2026-06-10: 1Technical Details · 2026-06-18: 2Technical Details · 2026-06-25: 1Technical Details · 2026-07-29: 1Technical Details · 2026-08-07: 105-2605-3005-3106-0106-0206-0306-0406-0506-0606-0806-0906-1006-1806-2406-2507-2908-0709-2810-07
Signal classification5 categories
Active Exploitation
5176.1%
Patch
69.0%
General
57.5%
Disclosure
46.0%
PoC
11.5%
Referenced assets54 URLs
By indicator
Classification over time
DateTotalLabels
2026-05-261
Patch1
2026-05-301
General1
2026-05-311
Patch1
2026-06-012
Active Exploitation1PoC1
2026-06-021
Patch1
2026-06-033
Active Exploitation2Disclosure1
2026-06-0425
Active Exploitation24Patch1
2026-06-056
Active Exploitation5General1
2026-06-063
Active Exploitation2Disclosure1
2026-06-085
Active Exploitation5
2026-06-096
Active Exploitation5Disclosure1
2026-06-106
Active Exploitation4General2
2026-06-182
Active Exploitation1Disclosure1
2026-06-241
Active Exploitation1
2026-06-251
Patch1
2026-07-291
Patch1
2026-08-071
Active Exploitation1
2026-09-281
General1
Full discourse20 posts
  • The Hacker News@TheHackersNews
    Active Exploitation

    🚨 Attackers are actively exploiting CVE-2026-45247, a critical Magento RCE flaw in Mirasvit Cache Warmer. CISA added it to KEV. The bug scores 9.8 CVSS and allows unauthenticated PHP code execution via crafted CacheWarmer cookies. Patch before June 6. Read: https://thehackernews.com/2026/06/cisa-adds-exploited-magento-rce-flaw.html

    Post summary

    CVE-2026-45247 is an actively exploited Magento RCE vulnerability with a 9.8 CVSS score, for which a patch is available before June 6.

    3252691110.8K
    2.0M followersView on X
  • CISA Cyber@CISACyber
    Active Exploitation

    🛡️ We added Mirasvit Full Page Cache Warmer deserialization of untrusted data vulnerability CVE-2026-45247 to our Known Exploited Vulnerabilities Catalog. Visit https://go.dhs.gov/Z3Q & apply mitigations to protect your org from cyberattacks. #Cybersecurity #InfoSec https://t.co/nSR71c2CvX

    Post summary

    The tweet flags CVE-2026-45247 as a known exploited vulnerability, urging users to apply mitigations to defend against attacks.

    3902044.5K
    300.1K followersView on X
  • Teegra 🧝‍♀️𝕏@Teeegra
    Active Exploitation

    آژانس امنیت سایبری و زیرساخت آمریکا (CISA) یک آسیب‌پذیری بحرانی در افزونه Mirasvit Cache Warmer، یک افزونه محبوب کش صفحه کامل (full-page cache) برای پلتفرم Magento را به فهرست آسیب‌پذیری‌های شناخته‌شده مورد بهره‌برداری (KEV) خود اضافه کرد. این آسیب‌پذیری با شناسه CVE-2026-45247 و امتیاز بحرانی ۹.۸ از ۱۰، ناشی از بی‌سریال‌سازی داده‌های غیرقابل اعتماد (deserialization of untrusted data) است و به مهاجمان احراز هویت‌نشده اجازه می‌دهد از طریق ارسال یک کوکی CacheWarmer دستکاری‌شده کد PHP دلخواه را از راه دور روی سرور هدف اجرا کنند. این نقص تمام نسخه‌های افزونه پیش از نسخه ۱.۱۱.۱۲ را تحت تأثیر قرار می‌دهد

    Post summary

    CISA has listed CVE-2026-45247 as a known exploited vulnerability affecting all Mirasvit Cache Warmer versions before 1.11.12, with no mention of PoC, exploit code, patch, or debunking.

    000134927
    19.1K followersView on X
  • ET Labs@ET_Labs
    General

    26 new OPEN, 35 new PRO (26 + 9) Thanks @skocherhan, @500mk500 for the Clickfix IOCs. Mirasvit (CVE-2026-45247), Rails Active Storage (CVE-2026-66066), Zbtlink Router ENDLESSDOORS Shell Outbound (rctlbash), TA569, TA584, and more. https://community.emergingthreats.net/t/ruleset-update-summary-2026-09-28-v11299/3467

    Post summary

    The message lists several CVEs as part of Clickfix IOCs but provides no PoC, exploit details, patches, or active exploitation information, serving only as a general reference to the vulnerabilities.

    02001299
    5.7K followersView on X
  • Elusive@ElusivePrivacy
    Active Exploitation

    CISA KEV roundup: Linux cgroups escape, Android Framework, Magento RCE all actively exploited Three additions to CISA's Known Exploited Vulnerabilities catalog this week: CVE-2022-0492 (Linux kernel cgroups v1, container escape via improper auth), CVE-2025-48595 (Android Framework integer overflow), and CVE-2026-45247 (Mirasvit Full Page Cache Warmer for Magento 2 unauthenticated RCE via PHP object injection in CacheWarmer cookie, patched in v1.11.12). Feds have 21 days to patch. Source: CISA / BleepingComputer Full analysis → http://t.me/VulnerabilityNews Follow @VulnerabilityNw

    Post summary

    CISA reports three CVEs – Linux cgroups container escape, Android Framework integer overflow, and Magento 2 RCE – as actively exploited, noting patch availability for the Magento issue and a 21‑day deadline for federal responders.

    11010140
    185 followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(6/3追加) 🛡 No. 1612 CVE-2026-45247 Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data Vulnerability ================================== ✅概要 ・深刻度:緊急 9.3 (CVSS Base) / VulnCheck (CNA) ・種別:信頼できないデータのデシリアライゼーション (CWE-502) ・CVSS:CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Mirasvit Full Page Cache Warmer for Magento 2 の 1.11.12 より前のバージョンに存在する PHP オブジェクトインジェクションの脆弱性です。 事前認証されていない攻撃者が CacheWarmer Cookie に細工したシリアライズ済み PHP オブジェクトを指定することで、Magento および依存関係に含まれるガジェットチェーンを悪用し、サーバ上で任意コードを実行される恐れがあります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:低 ✅攻撃前提条件 ・Mirasvit Full Page Cache Warmer for Magento 2 の 1.11.12 より前のバージョンを使用している ・Magento または Adobe Commerce のストアフロントに外部から HTTP リクエストを送信できる ・攻撃者が CacheWarmer Cookie に細工したシリアライズ済み PHP オブジェクトを指定できる ・修正済みバージョンが適用されていない ✅悪用時影響 ・リモートコード実行 ・サーバ上での任意コマンド実行 ・Magento / Adobe Commerce 環境の侵害 ・Web シェル設置や追加ペイロード展開につながる ✅悪用事例等に関する公開情報 ・PoC/Exploit:一部公開(技術情報のみ) ・ITW:確認済み(Imperva) ・Sansec は、CacheWarmer Cookie の値が PHP の unserialize() に渡され、Magento および依存関係のガジェットチェーンと組み合わせてリモートコード実行に至る技術情報を公開。Imperva は、CVE-2026-45247 を悪用しようとするシリアライズ済み PHP オブジェクトのペイロードを含む HTTP リクエストを観測。 ✅関連情報 ・https://nvd.nist.gov/vuln/detail/CVE-2026-45247 ・https://mirasvit.com/package/changelog/?package=mirasvit/module-cache-warmer ・https://sansec.io/research/mirasvit-cache-warmer-object-injection ・https://www.vulncheck.com/advisories/mirasvit-cache-warmer-for-magento-php-object-injection ・https://www.imperva.com/blog/imperva-customers-protected-against-cve-2026-45247-in-mirasvit-full-page-cache-warmer-for-magento/ https://www.cisa.gov/news-events/alerts/2026/06/03/cisa-adds-one-known-exploited-vulnerability-catalog #vulnerability

    Post summary

    CVE‑2026‑45247, a high‑severity PHP object injection in Mirasvit Full Page Cache Warmer, has been confirmed exploited in the wild with PoC details available, but no patch or workaround is explicitly mentioned.

    000214.2K
    43.4K followersView on X
  • Elusive@ElusivePrivacy
    Active Exploitation

    🔓 CVE-2026-45247, CVSS 9.8. Unauthenticated PHP object injection in Mirasvit Full Page Cache Warmer for Magento 2 enables remote code execution. Actively exploited in the wild to deploy web shells and create admin accounts. Thousands of Adobe Commerce storefronts affected. Patch: v1.1.52. Source: SecurityWeek / Sansec Full analysis → http://t.me/VulnerabilityNews Follow @VulnerabilityNw

    Post summary

    CVE-2026-45247 is a high‑severeness PHP object injection flaw in Mirasvit Full Page Cache Warmer, actively exploited to deploy web shells and create admin accounts on Magento 2 sites, with a vendor patch (v1.1.52) available.

    0101069
    186 followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-45247 2 - CVE-2026-27914 3 - CVE-2017-11882 4 - CVE-2026-45495 5 - CVE-2026-0826 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The message lists five CVEs as trending but offers no exploitation, patch, or technical information.

    0002099
    1.7K followersView on X
  • BnSnK@BunSnack
    Active Exploitation

    CVE-2026-45247: PHP object injection in Mirasvit Cache Warmer for Magento. CVSS 9.8, actively exploited, CISA KEV. Send a crafted cookie, get RCE. Thousands of stores at risk.

    Post summary

    CVE‑2026‑45247 is a high‑severity PHP object injection flaw in Mirasvit Cache Warmer for Magento, scored CVSS 9.8, actively exploited in the wild, and flagged by CISA as a KEV.

    0002035
    6 followersView on X
  • SecAlerts@SecAlertsCo
    Patch

    Unauthenticated RCE in Mirasvit Cache Warmer for Magento 2. CVE-2026-45247 (CVSS 9.3) lets attackers exploit PHP object injection with zero privileges. Update to v1.11.12 now. #Magento #Security https://secalerts.co/vulnerability/CVE-2026-45247 https://t.co/H51n1Jl1V4

    Post summary

    The message highlights a critical unauthenticated RCE in Mirasvit Cache Warmer and urges users to upgrade to v1.11.12 to mitigate CVE-2026-45247.

    10010124
    825 followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-45247 — CVSS 9.8/10 ██████████ Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/jyam8S6TLa

    Post summary

    The tweet announces CVE‑2026‑45247, a critical PHP object injection flaw in Mirasvit Full Page Cache Warmer, and urges users to apply the available patch.

    11000137
    43 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    00:14 UTC: Thread live on @lyrie_ai. CVE-2026-45247 added to CISA KEV: Mirasvit Mirasvit Full Page Cache Warmer

    Post summary

    CVE‑2026‑45247, linked to Mirasvit Full Page Cache Warmer, has been added to the CISA KEV list, indicating a recognized vulnerability but without further technical or exploitation details.

    1000023
    258 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    03:00 UTC: First exploit attempt in the wild. CVE-2026-45247 added to CISA KEV: Mirasvit Mirasvit Full Page Cache Warmer

    Post summary

    CISA KEV notes CVE-2026-45247 for Mirasvit Full Page Cache Warmer and reports the first exploit attempt in the wild at 03:00 UTC.

    1000036
    258 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    00:11 UTC: GPT-5 enrichment complete. 102 words. 3 citations. CVE-2026-45247 added to CISA KEV: Mirasvit Mirasvit Full Page Cache Warmer

    Post summary

    CVE‑2026‑45247 has been added to the CISA KEV list for Mirasvit Full Page Cache Warmer, indicating it is currently being exploited in the wild.

    1000022
    258 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    00:03 UTC: Lyrie Sentinel flagged it. CVE-2026-45247 added to CISA KEV: Mirasvit Mirasvit Full Page Cache Warmer

    Post summary

    The text reports that CVE-2026-45247, affecting Mirasvit Full Page Cache Warmer, has been added to the CISA KEV list, but contains no technical details or exploitation evidence.

    1000025
    258 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    00:00 UTC: CVE-2026-45247 disclosed. CISA: CVE-2026-45247 added to Known Exploited Vulnerabilities — Mirasvit Mirasvit Full Page Cache Warmer CVE-2026-45247 added to CISA KEV: Mirasvit Mirasvit Full Page Cache Warmer

    Post summary

    CISA has listed CVE‑2026‑45247 in its Known Exploited Vulnerabilities and KEV, confirming active exploitation against Mirasvit Full Page Cache Warmer.

    1000034
    258 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    Source: X search for CVE-2026 critical Posted: 2026-06-04T07:20:01.000Z Likes: 57 0day Intel: 🚨 Attackers are actively exploiting CVE-2026-45247, a critical Magento RCE flaw

    Post summary

    The post claims attackers are currently exploiting CVE-2026-45247, a critical remote code execution vulnerability in Magento.

    1000049
    258 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    CVE-2026-45247: 🚨 Attackers are actively exploiting CVE-2026-45247, a critical Magento RCE flaw in Mirasvit Cache Warmer. CISA added it to KEV. The bug scores 9.8 CVSS and allows unauthenticated PHP code execution via crafted CacheWarmer cookies. Patch before June 6.…

    Post summary

    The post reports that attackers are actively exploiting the critical Magento RCE flaw CVE-2026-45247 and urges patching before June 6.

    1000037
    258 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    Full Tweet 🚨 Attackers are actively exploiting CVE-2026-45247, a critical Magento RCE flaw in Mirasvit Cache Warmer. 0day Intel: 🚨 Attackers are actively exploiting CVE-2026-45247, a critical Magento RCE flaw

    Post summary

    The tweet reports that attackers are exploiting the Magento RCE vulnerability CVE‑2026‑45247 in the Mirasvit Cache Warmer plugin, indicating ongoing active exploitation in the wild.

    1000051
    258 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    0day Intel: 🚨 Attackers are actively exploiting CVE-2026-45247, a critical Magento RCE flaw

    Post summary

    The tweet claims that CVE-2026-45247, a critical Magento remote code execution flaw, is being actively exploited in the wild, but provides no PoC, exploit tool, patch, or debunking information.

    1000042
    258 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmirasvitfull_page_cache_warmer-magento-

Explore more