PT-2026-43258 · Mirasvit · Full Page Cache Warmer

·

CVE-2026-45247

·

Published

2026-05-26

·

Updated

2026-06-25

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Mirasvit Full Page Cache Warmer for Magento 2 versions prior to 1.11.12
Description A PHP object injection issue exists due to the unrestricted use of the native unserialize() function. Unauthenticated attackers can achieve remote code execution by providing a crafted serialized PHP object within the CacheWarmer cookie, leveraging gadget chains available in Magento and its dependencies. This flaw has been actively exploited in the wild to deploy web shells and create administrative accounts, affecting thousands of Adobe Commerce storefronts.
Recommendations Update to version 1.11.12 or later. As a temporary mitigation, restrict or monitor the use of the CacheWarmer cookie to minimize the risk of exploitation.

Fix

RCE

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-45247

Affected Products

Full Page Cache Warmer