Executive Summary
In May 2026, a critical vulnerability (CVE-2026-45247) was identified in Mirasvit's Full Page Cache Warmer extension for Magento 2, versions prior to 1.11.12. This flaw allows unauthenticated attackers to execute arbitrary code on affected servers by exploiting a PHP object injection via the 'CacheWarmer' cookie. The vulnerability arises from the unsafe use of PHP's 'unserialize()' function, enabling remote code execution without authentication. (sansec.io)
The inclusion of this vulnerability in CISA's Known Exploited Vulnerabilities catalog underscores its active exploitation and the significant risk it poses to e-commerce platforms. Organizations using the affected versions are urged to update to version 1.11.12 immediately to mitigate potential breaches and data compromises. (blog.gridinsoft.com)
Why This Matters Now
The active exploitation of CVE-2026-45247 highlights the critical need for immediate patching to prevent unauthorized access and potential data breaches in Magento-based e-commerce platforms.
Attack Path Analysis
An unauthenticated attacker exploited a deserialization vulnerability in the Mirasvit Full Page Cache Warmer for Magento 2, leading to remote code execution. The attacker then escalated privileges by leveraging the compromised server to gain administrative access. Using the elevated privileges, the attacker moved laterally to other systems within the network. The attacker established a command and control channel to maintain persistent access. Sensitive data was exfiltrated from the compromised systems. Finally, the attacker deployed ransomware, encrypting critical data and disrupting business operations.
Kill Chain Progression
Initial Compromise
Description
An unauthenticated attacker exploited a deserialization vulnerability in the Mirasvit Full Page Cache Warmer for Magento 2, leading to remote code execution.
Related CVEs
CVE-2026-45247
CVSS 9.8Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that allows unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the CacheWarmer cookie.
Affected Products:
Mirasvit Full Page Cache Warmer for Magento 2 – < 1.11.12
Exploit Status:
exploited in the wildReferences:
https://nvd.nist.gov/vuln/detail/CVE-2026-45247https://mirasvit.com/package/changelog/?package=mirasvit/module-cache-warmerhttps://sansec.io/research/mirasvit-cache-warmer-object-injectionhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-45247https://www.imperva.com/blog/imperva-customers-protected-against-cve-2026-45247-in-mirasvit-full-page-cache-warmer-for-magento/https://www.vulncheck.com/advisories/mirasvit-cache-warmer-for-magento-php-object-injection
MITRE ATT&CK® Techniques
Command and Scripting Interpreter: PHP
Exploitation for Client Execution
Exploit Public-Facing Application
Server Software Component: Web Shell
Valid Accounts
Account Discovery: Domain Account
OS Credential Dumping: LSASS Memory
Data Destruction
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components are protected from known vulnerabilities
Control ID: 6.2
NYDFS 23 NYCRR 500 – Access Privileges
Control ID: 500.07
DORA – ICT Risk Management Framework
Control ID: Article 6
CISA ZTMM 2.0 – Identity Management
Control ID: Pillar 1: Identity
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
CVE-2026-45247 Mirasvit Full Page Cache Warmer deserialization vulnerability directly threatens web applications requiring urgent remediation and enhanced egress security controls.
E-Learning
Online platforms using Mirasvit cache components face active exploitation risks, requiring immediate patching and zero trust segmentation to protect educational data.
Internet
Web service providers must prioritize KEV catalog vulnerability remediation with inline IPS and threat detection to prevent deserialization attacks targeting infrastructure.
Government Administration
Federal agencies under BOD 22-01 mandate must remediate this known exploited vulnerability by due date using multicloud visibility and anomaly detection.
Sources
- CISA Adds One Known Exploited Vulnerability to Cataloghttps://www.cisa.gov/news-events/alerts/2026/06/03/cisa-adds-one-known-exploited-vulnerability-catalogVerified
- Mirasvit Full Page Cache Warmer for Magento 2 Changeloghttps://mirasvit.com/package/changelog/?package=mirasvit/module-cache-warmerVerified
- Mirasvit Cache Warmer Object Injection Vulnerabilityhttps://sansec.io/research/mirasvit-cache-warmer-object-injectionVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it likely limits the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and controlled egress policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's ability to exploit the deserialization vulnerability may be constrained by CNSF's identity-aware controls, which could limit unauthorized access to critical workloads.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges could be limited by Zero Trust Segmentation, which may restrict access to administrative interfaces and sensitive resources.
Control: East-West Traffic Security
Mitigation: The attacker's lateral movement may be constrained by East-West Traffic Security, which could limit unauthorized communication between workloads.
Control: Multicloud Visibility & Control
Mitigation: The attacker's ability to establish command and control channels could be limited by Multicloud Visibility & Control, which may detect and restrict unauthorized outbound communications.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's data exfiltration efforts may be constrained by Egress Security & Policy Enforcement, which could limit unauthorized data transfers.
The attacker's deployment of ransomware may be limited in scope due to CNSF's segmentation policies, which could restrict the spread of malicious payloads.
Impact at a Glance
Affected Business Functions
- E-commerce Platform
- Online Sales Transactions
- Customer Account Management
Estimated downtime: 7 days
Estimated loss: $50,000
Potential exposure of customer personal and payment information.
Recommended Actions
Key Takeaways & Next Steps
- • Implement inline intrusion prevention systems (IPS) to detect and block exploitation attempts of known vulnerabilities.
- • Enforce zero trust segmentation to limit lateral movement within the network.
- • Deploy egress security and policy enforcement to monitor and control outbound traffic, preventing unauthorized data exfiltration.
- • Utilize threat detection and anomaly response systems to identify and respond to suspicious activities promptly.
- • Regularly update and patch software to mitigate known vulnerabilities and reduce the attack surface.



