SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2026-45247

Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data Vulnerability

KEVCRITICAL 9.3EPSS 27.5%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 6 June 2026). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that allows unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the CacheWarmer cookie. Attackers can exploit the unrestricted call to PHP's native unserialize() function combined with gadget chains available in Magento and its dependencies to execute arbitrary code on the server.

CVSS 4.0
9.3 CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
EPSS
27.55% probability · 98th percentile
Public exploits
None in Exploit-DB
CISA KEV
Listed 3 June 2026 · due 6 June 2026
Weakness
CWE-502
Affected
mirasvit/full page cache warmer
Source
disclosure@vulncheck.com
EPSS trend
0%15%30%21 September 2026: 27.55%21 September 202621 September 2026

EPSS 27.5% since 21 September 2026; no change recorded yet. The dashed line is the ten per cent mark our analysts treat as “patch before the next change window”. Points are recorded when the score first appears and whenever it moves by a percentage point or more.

CISA notes

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. https://mirasvit.com/package/changelog/?package=mirasvit/module-cache-warmer ; https://nvd.nist.gov/vuln/detail/CVE-2026-45247

Source: NVD record, EPSS from FIRST.org, KEV from CISA, exploits from Exploit-DB. Refreshed daily. Download this record as JSON.