LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-45247: Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jun 3, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jun 6, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-45247 to its Known Exploited Vulnerabilities catalog on Jun 3, 2026, with a federal patch deadline of Jun 6, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Mirasvit Full Page Cache Warmer contains a deserialization of untrusted data vulnerability that could allow unauthenticated attackers to achieve remote code execution by supplying a crafted serialized…

This vulnerability affects the Mirasvit Full Page Cache Warmer extension and stems from unsafe handling of serialized data. Unauthenticated attackers can supply a crafted serialized PHP object through the CacheWarmer cookie to achieve remote code execution on the server.

The issue is tracked as CVE-2026-45247 and classified under CWE-502. Because the flaw permits code execution without authentication, it can lead to full server compromise if exploited.

How it works

The weakness is deserialization of untrusted data. The application accepts a serialized PHP object in the CacheWarmer cookie and reconstructs it without sufficient validation or type restrictions.

Am I affected? How to find it in your systems

Inventory all instances of the Mirasvit Full Page Cache Warmer extension in your Magento or PHP web environments. Examine installed modules, composer manifests, and file-system directories for the extension code.

How to remediate

Apply mitigations per the vendor instructions referenced in the advisory. The primary action is to update the extension to a version that addresses the deserialization flaw.

If you can't patch immediately

Until a patch can be applied, implement compensating controls to limit exposure.

If your data may have been exposed

Actively exploited deserialization vulnerabilities have led to breaches in similar products. Review server access logs for suspicious CacheWarmer cookie activity and examine systems for unauthorized code execution or persistence mechanisms.

Run a free exposure scan of your email addresses to check known breach data associated with this or related incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMirasvit · Mirasvit Full Page Cache Warmer
WeaknessCWE-502
Added to CISA KEVJun 3, 2026
Federal patch deadlineJun 6, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities