ctipilot.ch
← Back to Daily brief 2026-06-04
HIGHCVE-2026-45247exploitedvulnerability

CVE-2026-45247 — Mirasvit Full Page Cache Warmer (Magento 2 / Adobe Commerce): unauthenticated PHP object-injection RCE, now in CISA KEV

discovered 2026-06-04 05:00 UTCrun 2026-06-04-51b23ffa2 sourcesmulti-source

Versions below 1.11.12 pass the attacker-controlled CacheWarmer cookie to PHP's native unserialize() without restricting instantiable classes, letting an unauthenticated attacker trigger gadget chains in Magento's Laminas/Zend dependency tree for remote code execution from any storefront page — "no authentication, no admin session and no config toggle required" (Sansec, 2026-05-26). Sansec discovered the flaw and shipped a detection rule on 24 April under coordinated disclosure (patch 25 May); Imperva has since observed active exploitation campaigns delivering base64-encoded serialized objects (Imperva, 2026-05-29). CISA added it to KEV on 2026-06-03. Successful exploitation yields web-root access for webshell persistence (T1505.003) and .env / config/env.php credential theft. Fix: upgrade to ≥1.11.12; interim, block or sanitise the CacheWarmer cookie at the WAF/reverse proxy.

no authentication, no admin session and no config toggle required

Sansec

Defender actions

  • Patch the actively-exploited web CVEs today. Mirasvit Cache Warmer → ≥1.11.12 or WAF-block the CacheWarmer cookie (CVE-2026-45247, KEV/ITW); WordPress Kirki → ≥6.0.7 and Burst Statistics → ≥3.4.2, then hunt for rogue admin-account creation and unauthenticated REST calls (CVE-2026-8206 / CVE-2026-8181). (§ 2)

ATT&CK mapping

1 technique mapped from the cited reporting · MITRE ATT&CK v19.1

Persistence TA0003
T1505.003Server Software Component: Web Shell

Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server.

overlap matrix · ATT&CK page ↗

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.