---
schema: 1
kind: vulnerability
title: "CVE-2026-45247 — Mirasvit Full Page Cache Warmer (Magento 2 / Adobe Commerce): unauthenticated PHP object-injection RCE, now in CISA KEV"
headline: "CVE-2026-45247 — Mirasvit Full Page Cache Warmer (Magento 2 / Adobe Commerce): unauthenticated PHP object-injection RCE, now in CISA KEV"
summary: "Magento object-injection RCE is in CISA KEV and exploited in the wild. CVE-2026-45247 in the Mirasvit Full Page Cache Warmer extension deserializes the CacheWarmer cookie with no auth → unauthenticated RCE; CISA KEV-listed and exploitation confirmed by Imperva, fix is v1.11.12 (Sansec, 2026-05-26)."
discovered_at: "2026-06-04T05:00:05Z"
event_date: 2026-05-29
run_id: 2026-06-04-51b23ffa
priority: high
immediate_action: null
tags:
  - vulnerabilities
  - actively-exploited
  - rce
  - pre-auth
  - cisa-kev
  - patch-available
regions:
  - global
sectors:
  - retail
  - public-sector
entities: []
cves:
  - id: CVE-2026-45247
    cvss: "9.8"
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status:
      - exploited
      - cisa-kev
      - patch-available
sources:
  - url: "https://sansec.io/research/mirasvit-cache-warmer-object-injection"
    publisher: Sansec
    role: primary
  - url: "https://www.imperva.com/blog/imperva-customers-protected-against-cve-2026-45247-in-mirasvit-full-page-cache-warmer-for-magento/"
    publisher: Imperva
    role: corroborating
closed_sources: []
evidence:
  - quote: "no authentication, no admin session and no config toggle required"
    publisher: Sansec
verification: multi-source
sourcing_note: null
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions:
  - "**Patch the actively-exploited web CVEs today.** Mirasvit Cache Warmer → ≥1.11.12 or WAF-block the `CacheWarmer` cookie (CVE-2026-45247, KEV/ITW); WordPress Kirki → ≥6.0.7 and Burst Statistics → ≥3.4.2, then hunt for rogue admin-account creation and unauthenticated REST calls (CVE-2026-8206 / CVE-2026-8181). (§ 2)"
migrated_from: briefs/2026-06-04.md
---

Versions below 1.11.12 pass the attacker-controlled `CacheWarmer` cookie to PHP's native `unserialize()` without restricting instantiable classes, letting an unauthenticated attacker trigger gadget chains in Magento's Laminas/Zend dependency tree for remote code execution from any storefront page — "no authentication, no admin session and no config toggle required" ([Sansec, 2026-05-26](https://sansec.io/research/mirasvit-cache-warmer-object-injection)). Sansec discovered the flaw and shipped a detection rule on 24 April under coordinated disclosure (patch 25 May); Imperva has since observed active exploitation campaigns delivering base64-encoded serialized objects ([Imperva, 2026-05-29](https://www.imperva.com/blog/imperva-customers-protected-against-cve-2026-45247-in-mirasvit-full-page-cache-warmer-for-magento/)). CISA added it to KEV on 2026-06-03. Successful exploitation yields web-root access for webshell persistence (`T1505.003`) and `.env` / `config/env.php` credential theft. Fix: upgrade to ≥1.11.12; interim, block or sanitise the `CacheWarmer` cookie at the WAF/reverse proxy.
