CVE-2026-45247
Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 6 June 2026). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that allows unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the CacheWarmer cookie. Attackers can exploit the unrestricted call to PHP's native unserialize() function combined with gadget chains available in Magento and its dependencies to execute arbitrary code on the server.
- CVSS 4.0
- 9.3 CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 27.55% probability · 98th percentile
- Public exploits
- None in Exploit-DB
- CISA KEV
- Listed 3 June 2026 · due 6 June 2026
- Weakness
- CWE-502
- Affected
- mirasvit/full page cache warmer
- Source
- disclosure@vulncheck.com
EPSS 27.5% since 21 September 2026; no change recorded yet. The dashed line is the ten per cent mark our analysts treat as “patch before the next change window”. Points are recorded when the score first appears and whenever it moves by a percentage point or more.
CISA notes
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. https://mirasvit.com/package/changelog/?package=mirasvit/module-cache-warmer ; https://nvd.nist.gov/vuln/detail/CVE-2026-45247
References
- https://mirasvit.com/package/changelog/?package=mirasvit/module-cache-warmerRelease Notes
- https://sansec.io/research/mirasvit-cache-warmer-object-injectionThird Party Advisory
- https://www.vulncheck.com/advisories/mirasvit-cache-warmer-for-magento-php-object-injectionThird Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-45247US Government Resource
- https://www.imperva.com/blog/imperva-customers-protected-against-cve-2026-45247-in-mirasvit-full-page-cache-warmer-for-magento/Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA, exploits from Exploit-DB. Refreshed daily. Download this record as JSON.