news.mlab.sh
Back to the feed
vulnerability

CISA Adds Exploited Magento RCE Flaw CVE-2026-45247 to KEV Catalog

Critical
Summary

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability, CVE-2026-45247, affecting the Mirasvit Cache Warmer Magento extension to its KEV catalog. This flaw allows for remote code execution via deserialization of untrusted data, and is currently being actively exploited. Organizations using the vulnerable extension are urged to apply the available patches immediately.

A critical vulnerability was discovered in the Mirasvit Cache Warmer Magento extension, allowing attackers to execute arbitrary PHP code on affected servers. The vulnerability, CVE-2026-45247, is a deserialization issue triggered by a crafted serialized PHP object within the CacheWarmer cookie. Sansec identified approximately 6,000 stores utilizing the extension, though the actual number is likely higher due to the use of CDNs. Imperva has observed active exploitation attempts, utilizing base64-encoded serialized PHP object payloads to trigger remote code execution via common gadget chains.

The exploitation is primarily targeting gaming and business websites, with a focus on the U.S., the U.K., France, and Australia. While the exact actors behind the attacks are currently unknown, the objective appears to be identifying vulnerable Magento environments and validating the possibility of remote code execution. FCEB agencies are under orders to apply the patches by June 6, 2026, and site owners are advised to monitor for suspicious CacheWarmer cookie requests.

Read the full article at The Hacker News