A critical vulnerability in the Mirasvit Cache Warmer extension for Magento and Adobe Commerce allows unauthenticated attackers to trigger PHP object injection and potentially achieve remote code execution through a crafted CacheWarmer cookie. The flaw, tracked as CVE-2026-45247 and rated 9.8, is caused by unsafe deserialization of attacker-controlled data via PHP unserialize() during normal storefront requests, meaning exploitation does not require an admin session or prior authentication.
Mirasvit released version 1.11.12 to fix the issue, which affects earlier versions of the extension. Researchers said roughly 6,000 stores appear to be running Mirasvit extensions, with the real number potentially higher because CDNs can obscure detection. Defenders were urged to patch immediately, review logs for suspicious base64-encoded serialized object markers such as Tz, Qz, or YT in CacheWarmer cookie values, block exploitation attempts, and investigate for follow-on compromise including webshells, backdoors, and other malware.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
CISA added the Mirasvit Cache Warmer flaw CVE-2026-45247 to its Known Exploited Vulnerabilities catalog after reports of active exploitation. The agency directed Federal Civilian Executive Branch agencies to remediate the issue by 2026-06-06.
Sansec disclosed a critical vulnerability in the Mirasvit Cache Warmer extension affecting versions before 1.11.12, caused by unsafe unserialization of attacker-controlled data in the CacheWarmer cookie. The advisory said the issue requires no authentication, can enable remote code execution, and included detection and remediation guidance.
Mirasvit released version 1.11.12 of its Cache Warmer extension to fix an unauthenticated PHP object injection flaw that can lead to remote code execution in Magento and Adobe Commerce storefronts.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
7 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcesecurityaffairs.com
Open sourcecybersecuritynews.com
Open sourcethehackernews.com
Open sourcecybersecuritynews.com
Open sourcesecurityonline.info
Open sourcesansec.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.