# Mirasvit Cache Warmer for Magento — Unauthenticated PHP Object Injection RCE (CVE-2026-45247, CVSS 9.8)

> Sansec disclosed an unauthenticated PHP object injection flaw (CWE-502) in the Mirasvit Full Page Cache Warmer extension for Magento 2 and Adobe Commerce. A crafted CacheWarmer cookie on any storefront request reaches PHP's native unserialize() on attacker-controlled data with no authentication; chained with Monolog POP gadgets it yields remote code execution. Imperva reports active in-the-wild exploitation across US, UK, France and Australia since disclosure.

- **Published:** 2026-06-01T00:00:00Z
- **Last reviewed:** 2026-06-01T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0651
- **ID:** TL-2026-0651
- **Severity:** CRITICAL (CVSS 9.8)
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 14 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-45247

## Description

CVE-2026-45247 is a critical (CVSS 3.1 base 9.8; CVSS 4.0 base 9.3) unauthenticated remote code execution vulnerability in the Mirasvit Full Page Cache Warmer extension for Magento 2 and Adobe Commerce, discovered by Sansec. The extension ships a storefront plugin that reads a client-supplied 'CacheWarmer' cookie to switch currency and customer session state before rendering, and passes the cookie value directly into PHP's native unserialize() function without any allowed-class restriction (no second-argument allowed_classes filter, no signature/HMAC, no authentication, no admin session, and no config toggle required). Because the vulnerable code path executes on every storefront request — not just warmer traffic — a single crafted cookie reaches the deserialization sink.

The injection is weaponized into code execution via a PHP object-injection (POP) gadget chain built from Monolog handler classes bundled as a Magento dependency: Monolog\Handler\SyslogUdpHandler, Monolog\Handler\BufferHandler, Monolog\Handler\FingersCrossedHandler, and Monolog\Handler\GroupHandler. The reconstructed object graph drives execution into PHP callables such as system() and current(), allowing arbitrary OS command execution in the web server context. Serialized PHP objects base64-encode to predictable leading bytes (Tz = O:, Qz = C:, YT = a:), so exploitation traffic carries a strong, regex-detectable signature: a CacheWarmer cookie whose value matches CacheWarmer:(Tz|Qz|YT).

Imperva observed active exploitation since public disclosure, with early-stage validation payloads — echo PWNED_CVE2026_$(date +%s) and sleep 5 — used by actors to confirm vulnerability presence before deploying further tooling. Targeting concentrated on gaming and business e-commerce sites in the United States, United Kingdom, France, and Australia. Sansec fingerprinted roughly 6,000 stores running Mirasvit extensions, with true exposure likely higher due to CDN masking. Successful RCE on a Magento 2 host enables full platform compromise: theft of customer PII and payment data (the historical objective of Magecart/digital-skimming actors who target Magento), website content modification, malicious code/webshell deployment, and denial of service.

Mirasvit notified on 2026-05-21 released patched version 1.11.12 on 2026-05-25; CVE-2026-45247 (GHSA-rg8p-9rpg-r32p) was assigned and published 2026-05-26, and the issue is tracked in the VulnCheck Known Exploited Vulnerabilities database. There is no authentication or user-interaction barrier, so all unpatched stores are at immediate risk.

## MITRE ATT&CK

- T1595 Active Scanning
- T1190 Exploit Public-Facing Application
- T1059 Command and Scripting Interpreter
- T1027 Obfuscated Files or Information
- T1505.003 Server Software Component: Web Shell
- T1005 Data from Local System
- T1071.001 Application Layer Protocol: Web Protocols
- T1565 Data Manipulation

## Sources

- [Critical vulnerability in Mirasvit Cache Warmer for Magento](https://sansec.io/research/mirasvit-cache-warmer-object-injection)
- [Imperva Customers Protected Against CVE-2026-45247 in Mirasvit Full Page Cache Warmer for Magento](https://www.imperva.com/blog/imperva-customers-protected-against-cve-2026-45247-in-mirasvit-full-page-cache-warmer-for-magento/)
- [NVD - CVE-2026-45247](https://nvd.nist.gov/vuln/detail/CVE-2026-45247)
- [Mirasvit Cache Warmer for Magento < 1.11.12 PHP Object Injection](https://www.vulncheck.com/advisories/mirasvit-cache-warmer-for-magento-php-object-injection)
- [GitHub Advisory GHSA-rg8p-9rpg-r32p](https://github.com/advisories/GHSA-rg8p-9rpg-r32p)
- [Critical Vulnerability Magento Cache Plugin Enables Remote Code Execution Attacks](https://cybersecuritynews.com/magento-cache-plugin-vulnerability/)
- [Critical Magento Cache Plugin Vulnerability Enables Remote Code Execution Attacks](https://gbhackers.com/magento-cache-plugin-vulnerability/)
- [Mirasvit Cache Warmer Changelog](https://mirasvit.com/package/changelog/?package=mirasvit/module-cache-warmer)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0651
