Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Microsoft Copilot Vulnerability Lets Attackers Hijack Accounts
August 4, 2026
Microsoft Hardens NuGet Security with Shorter API Key Lifespans
August 4, 2026
How SOCs Detect and Stop AI Phishing Attacks Bypassing Email Gateways
August 4, 2026
Home/CyberSecurity News/Critical Magento Cache Plugin Vulnerability Allows RCE Attacks
CyberSecurity News

Critical Magento Cache Plugin Vulnerability Allows RCE Attacks

Key Takeaways A critical unauthenticated remote code execution (RCE) vulnerability has been discovered in the Mirasvit Cache Warmer plugin for Magento and Adobe Commerce. The flaw, tracked as...

Sarah simpson
Sarah simpson
June 1, 2026 3 Min Read
61 0

Key Takeaways

  • A critical unauthenticated remote code execution (RCE) vulnerability has been discovered in the Mirasvit Cache Warmer plugin for Magento and Adobe Commerce.
  • The flaw, tracked as CVE-2026-45247, scores a maximum 9.8 CVSS (Critical) and allows attackers to execute arbitrary code without prior authentication or administrative access.
  • All versions of Mirasvit Cache Warmer prior to 1.11.12 are affected, impacting potentially thousands of e-commerce storefronts.
  • A patch (version 1.11.12) was released on May 25, 2026, and immediate updates are strongly recommended.

Critical RCE Flaw in Magento Cache Plugin

A severe security vulnerability has been identified in a widely deployed caching extension for Magento and Adobe Commerce platforms. This flaw permits threat actors to execute arbitrary code remotely on affected systems without needing any form of authentication, administrative privileges, or prior configuration changes.

Table Of Content

  • Key Takeaways
  • Critical RCE Flaw in Magento Cache Plugin
  • Understanding the Mirasvit Cache Warmer Vulnerability
  • What You Should Do

Security researchers at Sansec were responsible for uncovering this unauthenticated PHP object injection vulnerability within the Mirasvit Cache Warmer extension. This particular full-page cache extension is utilized by thousands of online storefronts built on Magento and Adobe Commerce.

The vulnerability, formally designated as CVE-2026-45247, has been assigned a critical CVSS score of 9.8, indicating the highest possible severity.

Understanding the Mirasvit Cache Warmer Vulnerability

Mirasvit Cache Warmer’s primary function is to proactively generate and store cached versions of e-commerce pages. This process optimizes performance for various user profiles, considering factors such as currency, customer groups, and other session-specific states.

To achieve this, the plugin packages certain session details into a cookie, which is then transmitted with each cache-warming request. Upon receiving these requests, the server-side component of the plugin reads the cookie’s contents and adjusts the session context accordingly before rendering the page.

The fundamental issue lies in how the plugin processes a specific portion of this cookie’s value. It directly feeds this value into PHP’s native unserialize() function without imposing any class restrictions or performing any authentication checks. Since the cookie’s content is entirely controlled by the client, an attacker can craft a malicious cookie value to inject arbitrary PHP objects, a technique known as PHP Object Injection (CWE-502).

When combined with a “gadget chain”—a sequence of existing classes and methods within Magento and its dependencies—this object injection can be escalated directly into full Remote Code Execution (RCE). The critical aspect of this attack is that it can be triggered by any request to the storefront, not just those related to internal cache-warming operations. This means any public-facing Magento store running the vulnerable plugin is a potential target.

All versions of Mirasvit Cache Warmer preceding 1.11.12 are susceptible to this vulnerability. It’s important to note that this extension is also bundled within several other Mirasvit packages, meaning many merchants may be unknowingly running the vulnerable component.

Sansec’s scanning efforts identified approximately 6,000 stores utilizing Mirasvit extensions. However, the actual number of affected installations is likely considerably higher, as content delivery networks (CDNs) like Cloudflare often obscure the underlying platform from external fingerprinting tools.

Organizations should review their web logs for indicators of compromise. Exploitation attempts typically leave a recognizable footprint, specifically storefront requests containing a CacheWarmer cookie whose value begins with CacheWarmer: followed by a base64-encoded string. Given that serialized PHP objects frequently base64-encode to strings starting with Tz, Qz, or YT, the pattern CacheWarmer:(Tz|Qz|YT) serves as a strong indicator of active exploitation.

What You Should Do

  • Update Immediately: Upgrade the Mirasvit Cache Warmer extension to version 1.11.12 or a newer release without delay. The patched version was made available on May 25, 2026.
  • Implement WAF Rules: Deploy or configure a web application firewall (WAF) to detect and block exploit attempts that leverage PHP object serialization.
  • Scan for Compromise: Conduct thorough scans of your Magento installation for any signs of compromise, including unexpected PHP files, webshells, or backdoors in web-accessible directories such as pub/.
  • Audit Installed Extensions: Verify if Mirasvit Cache Warmer is present, even if bundled within other Mirasvit modules, to ensure all instances are updated.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurityVulnerability

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

Critical IBM WebSphere CVE-2024-22987 Lets Attackers Remotely Execute Code

Next Post

Meta AI Bot Flaw Lets Attackers Reset Passwords, Hijack Instagram Accounts

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
DarkSword iOS Exploit Kit Spreads to 180 Websites and 27 Hosts
August 4, 2026
CISA Warns of Critical N-able N-central Auth Bypass (CVE-2023-47248) Exploited In Attacks
August 4, 2026
Critical CUPS Vulnerability (CVE-2023-4586) Lets Attackers Gain Root Privileges
August 4, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us