Threat reportVulnerabilityTL-2026-0651
Mirasvit Cache Warmer for Magento — Unauthenticated PHP Object Injection RCE (CVE-2026-45247, CVSS 9.8)
Mirasvit Cache Warmer for Magento (TL-2026-0651), also tracked as GHSA-rg8p-9rpg-r32p, is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-06-01. It has no confirmed attribution, affects Mirasvit Full Page Cache Warmer for Magento 2 / Adobe Commerce, references 1 CVE (CVE-2026-45247), maps to 8 MITRE ATT&CK techniques (T1005, T1027, T1059), and is covered by 9 detection rules and 14 indicators of compromise.
- CVSS
- 9.8/10Critical
- CVEs
- 1Referenced vulnerabilities
- Techniques
- 8MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 14Indicators of compromise
Key facts for TL-2026-0651
- Threat ID
- TL-2026-0651
- Also known as
- GHSA-rg8p-9rpg-r32p
- Severity
- CRITICAL
- CVSS
- 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- FINANCIAL
- Target sectors
- e-commerce, retail, gaming, business-services
- Target regions
- North America, Europe, Oceania
- Detection rules
- 9
- Indicators of compromise
- 14
Malware and tooling in Mirasvit Cache Warmer for Magento
Malware and tooling: Monolog\Handler\BufferHandler, Monolog\Handler\FingersCrossedHandler, Monolog\Handler\GroupHandler, Monolog\Handler\SyslogUdpHandler
How Mirasvit Cache Warmer for Magento works
Sansec disclosed an unauthenticated PHP object injection flaw (CWE-502) in the Mirasvit Full Page Cache Warmer extension for Magento 2 and Adobe Commerce. A crafted CacheWarmer cookie on any storefront request reaches PHP's native unserialize() on attacker-controlled data with no authentication; chained with Monolog POP gadgets it yields remote code execution. Imperva reports active in-the-wild exploitation across US, UK, France and Australia since disclosure.
CVE-2026-45247 is a critical (CVSS 3.1 base 9.8; CVSS 4.0 base 9.3) unauthenticated remote code execution vulnerability in the Mirasvit Full Page Cache Warmer extension for Magento 2 and Adobe Commerce, discovered by Sansec. The extension ships a storefront plugin that reads a client-supplied 'CacheWarmer' cookie to switch currency and customer session state before rendering, and passes the cookie value directly into PHP's native unserialize() function without any allowed-class restriction (no second-argument allowed_classes filter, no signature/HMAC, no authentication, no admin session, and no config toggle required). Because the vulnerable code path executes on every storefront request — not just warmer traffic — a single crafted cookie reaches the deserialization sink.
The injection is weaponized into code execution via a PHP object-injection (POP) gadget chain built from Monolog handler classes bundled as a Magento dependency: Monolog\Handler\SyslogUdpHandler, Monolog\Handler\BufferHandler, Monolog\Handler\FingersCrossedHandler, and Monolog\Handler\GroupHandler. The reconstructed object graph drives execution into PHP callables such as system() and current(), allowing arbitrary OS command execution in the web server context. Serialized PHP objects base64-encode to predictable leading bytes (Tz = O:, Qz = C:, YT = a:), so exploitation traffic carries a strong, regex-detectable signature: a CacheWarmer cookie whose value matches CacheWarmer:(Tz|Qz|YT).
Imperva observed active exploitation since public disclosure, with early-stage validation payloads — echo PWNED_CVE2026_$(date +%s) and sleep 5 — used by actors to confirm vulnerability presence before deploying further tooling. Targeting concentrated on gaming and business e-commerce sites in the United States, United Kingdom, France, and Australia. Sansec fingerprinted roughly 6,000 stores running Mirasvit extensions, with true exposure likely higher due to CDN masking. Successful RCE on a Magento 2 host enables full platform compromise: theft of customer PII and payment data (the historical objective of Magecart/digital-skimming actors who target Magento), website content modification, malicious code/webshell deployment, and denial of service.
Mirasvit notified on 2026-05-21 released patched version 1.11.12 on 2026-05-25; CVE-2026-45247 (GHSA-rg8p-9rpg-r32p) was assigned and published 2026-05-26, and the issue is tracked in the VulnCheck Known Exploited Vulnerabilities database. There is no authentication or user-interaction barrier, so all unpatched stores are at immediate risk.
MITRE ATT&CK techniques used in TL-2026-0651
Collection
Defense Evasion
T1027 Obfuscated Files or Information
Execution
T1059 Command and Scripting Interpreter
Command and Control
T1071.001 Application Layer Protocol: Web Protocols
Initial Access
T1190 Exploit Public-Facing Application
Persistence
T1505.003 Server Software Component: Web Shell
Impact
Reconnaissance
Affected products and versions in Mirasvit Cache Warmer for Magento
- Mirasvit — Full Page Cache Warmer for Magento 2 / Adobe Commerce (mirasvit/module-cache-warmer)
Vulnerable versions: < 1.11.12
Fixed in: 1.11.12
Remediation for Mirasvit Cache Warmer for Magento
Patches
- Mirasvit Cache Warmer 1.11.12 (released 2026-05-25)
Immediate actions
- Upgrade Mirasvit Full Page Cache Warmer to 1.11.12 or later immediately
- Block or strip inbound CacheWarmer cookies matching CacheWarmer:(Tz|Qz|YT) at the WAF/edge
- Hunt web/access logs for CacheWarmer cookies containing base64 serialized-object markers (Tz/Qz/YT) and for the echo PWNED_CVE2026_ and sleep test payloads
Workarounds
- WAF rule denying storefront requests whose CacheWarmer cookie value starts with Tz, Qz, or YT
- Remove/disable the Cache Warmer module if patching cannot be performed immediately
Longer-term hardening
- Inventory all Mirasvit modules — the vulnerable warmer ships bundled with several Mirasvit packages
- Deploy a virtual patch / WAF rule for PHP object-injection patterns on storefront cookies until patched
- Adopt PHP unserialize() allowed_classes hardening and prefer signed/JSON session payloads in custom code
- Deploy file-integrity monitoring and EDR on Magento hosts to catch post-exploitation webshells and skimmers
CVEs associated with Mirasvit Cache Warmer for Magento
Weaknesses (CWE) in Mirasvit Cache Warmer for Magento
Timeline of Mirasvit Cache Warmer for Magento
- Sansec discovers the unauthenticated PHP object injection vulnerability in Mirasvit Cache Warmer; Sansec Shield customers protected.
- Mirasvit notified of the vulnerability by Sansec under coordinated disclosure.
- Mirasvit releases patched version 1.11.12 adding allowed-class restriction on the CacheWarmer cookie deserialization path.
- Imperva observes active in-the-wild exploitation using Monolog gadget chains and echo/sleep validation payloads against gaming and business sites in US, UK, France, and Australia.
- CVE-2026-45247 (GHSA-rg8p-9rpg-r32p) assigned and publicly disclosed; Sansec research published with detection signature.
- Vulnerability tracked in the VulnCheck Known Exploited Vulnerabilities (KEV) database.
Sources cited for Mirasvit Cache Warmer for Magento
- Critical vulnerability in Mirasvit Cache Warmer for Magento
- Imperva Customers Protected Against CVE-2026-45247 in Mirasvit Full Page Cache Warmer for Magento
- NVD - CVE-2026-45247
- Mirasvit Cache Warmer for Magento < 1.11.12 PHP Object Injection
- GitHub Advisory GHSA-rg8p-9rpg-r32p
- Critical Vulnerability Magento Cache Plugin Enables Remote Code Execution Attacks
- Critical Magento Cache Plugin Vulnerability Enables Remote Code Execution Attacks
- Mirasvit Cache Warmer Changelog
Detection coverage for TL-2026-0651
As of 2026-06-01, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0651 across Splunk SPL, Microsoft KQL and Sigma, covering 14 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.