CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →
← Back to Daily brief 2026-06-04
HIGHCVE-2026-45247exploitedvulnerability

CVE-2026-45247, Mirasvit Full Page Cache Warmer (Magento 2 / Adobe Commerce): unauthenticated PHP object-injection RCE, now in CISA KEV

Defender actions

  • Patch the actively-exploited web CVEs today. Mirasvit Cache Warmer → ≥1.11.12 or WAF-block the CacheWarmer cookie (CVE-2026-45247, KEV/ITW); WordPress Kirki → ≥6.0.7 and Burst Statistics → ≥3.4.2, then hunt for rogue admin-account creation and unauthenticated REST calls (CVE-2026-8206 / CVE-2026-8181). (§ 2)

Analysis

Versions below 1.11.12 pass the attacker-controlled CacheWarmer cookie to PHP's native unserialize() without restricting instantiable classes, letting an unauthenticated attacker trigger gadget chains in Magento's Laminas/Zend dependency tree for remote code execution from any storefront page, "no authentication, no admin session and no config toggle required" (Sansec, 2026-05-26). Sansec discovered the flaw and shipped a detection rule on 24 April under coordinated disclosure (patch 25 May); Imperva has since observed active exploitation campaigns delivering base64-encoded serialized objects (Imperva, 2026-05-29). CISA added it to KEV on 2026-06-03. Successful exploitation yields web-root access for webshell persistence (T1505.003) and .env / config/env.php credential theft. Fix: upgrade to ≥1.11.12; interim, block or sanitise the CacheWarmer cookie at the WAF/reverse proxy.

Cited evidence

no authentication, no admin session and no config toggle required

Sansec

Sources2

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.