Threat reportVulnerabilityTL-2026-0651

Mirasvit Cache Warmer for Magento — Unauthenticated PHP Object Injection RCE (CVE-2026-45247, CVSS 9.8)

criticalACTIVE

Mirasvit Cache Warmer for Magento (TL-2026-0651), also tracked as GHSA-rg8p-9rpg-r32p, is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-06-01. It has no confirmed attribution, affects Mirasvit Full Page Cache Warmer for Magento 2 / Adobe Commerce, references 1 CVE (CVE-2026-45247), maps to 8 MITRE ATT&CK techniques (T1005, T1027, T1059), and is covered by 9 detection rules and 14 indicators of compromise.

CVSS
9.8/10Critical
CVEs
1Referenced vulnerabilities
Techniques
8MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
14Indicators of compromise

Key facts for TL-2026-0651

Threat ID
TL-2026-0651
Also known as
GHSA-rg8p-9rpg-r32p
Severity
CRITICAL
CVSS
9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
NONE
Motivation
FINANCIAL
Target sectors
e-commerce, retail, gaming, business-services
Target regions
North America, Europe, Oceania
Detection rules
9
Indicators of compromise
14

Malware and tooling in Mirasvit Cache Warmer for Magento

Malware and tooling: Monolog\Handler\BufferHandler, Monolog\Handler\FingersCrossedHandler, Monolog\Handler\GroupHandler, Monolog\Handler\SyslogUdpHandler

How Mirasvit Cache Warmer for Magento works

Sansec disclosed an unauthenticated PHP object injection flaw (CWE-502) in the Mirasvit Full Page Cache Warmer extension for Magento 2 and Adobe Commerce. A crafted CacheWarmer cookie on any storefront request reaches PHP's native unserialize() on attacker-controlled data with no authentication; chained with Monolog POP gadgets it yields remote code execution. Imperva reports active in-the-wild exploitation across US, UK, France and Australia since disclosure.

CVE-2026-45247 is a critical (CVSS 3.1 base 9.8; CVSS 4.0 base 9.3) unauthenticated remote code execution vulnerability in the Mirasvit Full Page Cache Warmer extension for Magento 2 and Adobe Commerce, discovered by Sansec. The extension ships a storefront plugin that reads a client-supplied 'CacheWarmer' cookie to switch currency and customer session state before rendering, and passes the cookie value directly into PHP's native unserialize() function without any allowed-class restriction (no second-argument allowed_classes filter, no signature/HMAC, no authentication, no admin session, and no config toggle required). Because the vulnerable code path executes on every storefront request — not just warmer traffic — a single crafted cookie reaches the deserialization sink.

The injection is weaponized into code execution via a PHP object-injection (POP) gadget chain built from Monolog handler classes bundled as a Magento dependency: Monolog\Handler\SyslogUdpHandler, Monolog\Handler\BufferHandler, Monolog\Handler\FingersCrossedHandler, and Monolog\Handler\GroupHandler. The reconstructed object graph drives execution into PHP callables such as system() and current(), allowing arbitrary OS command execution in the web server context. Serialized PHP objects base64-encode to predictable leading bytes (Tz = O:, Qz = C:, YT = a:), so exploitation traffic carries a strong, regex-detectable signature: a CacheWarmer cookie whose value matches CacheWarmer:(Tz|Qz|YT).

Imperva observed active exploitation since public disclosure, with early-stage validation payloads — echo PWNED_CVE2026_$(date +%s) and sleep 5 — used by actors to confirm vulnerability presence before deploying further tooling. Targeting concentrated on gaming and business e-commerce sites in the United States, United Kingdom, France, and Australia. Sansec fingerprinted roughly 6,000 stores running Mirasvit extensions, with true exposure likely higher due to CDN masking. Successful RCE on a Magento 2 host enables full platform compromise: theft of customer PII and payment data (the historical objective of Magecart/digital-skimming actors who target Magento), website content modification, malicious code/webshell deployment, and denial of service.

Mirasvit notified on 2026-05-21 released patched version 1.11.12 on 2026-05-25; CVE-2026-45247 (GHSA-rg8p-9rpg-r32p) was assigned and published 2026-05-26, and the issue is tracked in the VulnCheck Known Exploited Vulnerabilities database. There is no authentication or user-interaction barrier, so all unpatched stores are at immediate risk.

MITRE ATT&CK techniques used in TL-2026-0651

Collection

T1005 Data from Local System

Defense Evasion

T1027 Obfuscated Files or Information

Execution

T1059 Command and Scripting Interpreter

Command and Control

T1071.001 Application Layer Protocol: Web Protocols

Initial Access

T1190 Exploit Public-Facing Application

Persistence

T1505.003 Server Software Component: Web Shell

Impact

T1565 Data Manipulation

Reconnaissance

T1595 Active Scanning

Affected products and versions in Mirasvit Cache Warmer for Magento

  • Mirasvit — Full Page Cache Warmer for Magento 2 / Adobe Commerce (mirasvit/module-cache-warmer)
    Vulnerable versions: < 1.11.12
    Fixed in: 1.11.12

Remediation for Mirasvit Cache Warmer for Magento

Patches

  • Mirasvit Cache Warmer 1.11.12 (released 2026-05-25)

Immediate actions

  • Upgrade Mirasvit Full Page Cache Warmer to 1.11.12 or later immediately
  • Block or strip inbound CacheWarmer cookies matching CacheWarmer:(Tz|Qz|YT) at the WAF/edge
  • Hunt web/access logs for CacheWarmer cookies containing base64 serialized-object markers (Tz/Qz/YT) and for the echo PWNED_CVE2026_ and sleep test payloads

Workarounds

  • WAF rule denying storefront requests whose CacheWarmer cookie value starts with Tz, Qz, or YT
  • Remove/disable the Cache Warmer module if patching cannot be performed immediately

Longer-term hardening

  • Inventory all Mirasvit modules — the vulnerable warmer ships bundled with several Mirasvit packages
  • Deploy a virtual patch / WAF rule for PHP object-injection patterns on storefront cookies until patched
  • Adopt PHP unserialize() allowed_classes hardening and prefer signed/JSON session payloads in custom code
  • Deploy file-integrity monitoring and EDR on Magento hosts to catch post-exploitation webshells and skimmers

CVEs associated with Mirasvit Cache Warmer for Magento

CVE-2026-45247

Weaknesses (CWE) in Mirasvit Cache Warmer for Magento

CWE-502

Timeline of Mirasvit Cache Warmer for Magento

  • Sansec discovers the unauthenticated PHP object injection vulnerability in Mirasvit Cache Warmer; Sansec Shield customers protected.
  • Mirasvit notified of the vulnerability by Sansec under coordinated disclosure.
  • Mirasvit releases patched version 1.11.12 adding allowed-class restriction on the CacheWarmer cookie deserialization path.
  • Imperva observes active in-the-wild exploitation using Monolog gadget chains and echo/sleep validation payloads against gaming and business sites in US, UK, France, and Australia.
  • CVE-2026-45247 (GHSA-rg8p-9rpg-r32p) assigned and publicly disclosed; Sansec research published with detection signature.
  • Vulnerability tracked in the VulnCheck Known Exploited Vulnerabilities (KEV) database.

Sources cited for Mirasvit Cache Warmer for Magento

Detection coverage for TL-2026-0651

As of 2026-06-01, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0651 across Splunk SPL, Microsoft KQL and Sigma, covering 14 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
14 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats