Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical Magento RCE Flaw Added to CISA Vulnerability List

Critical Magento RCE Flaw Added to CISA Vulnerability List

Posted on June 4, 2026 By CWS

The Cybersecurity and Infrastructure Security Agency (CISA) has recently updated its Known Exploited Vulnerabilities (KEV) catalog to include a significant security flaw impacting Mirasvit Cache Warmer, a widely-used extension for Magento’s full-page caching. This decision follows reports of the flaw’s active exploitation in various online environments.

Understanding the Magento RCE Vulnerability

Identified as CVE-2026-45247 with a critical CVSS score of 9.8, this vulnerability arises from the deserialization of untrusted data, which can be manipulated to execute arbitrary PHP code on vulnerable servers. According to CISA, unauthenticated attackers can leverage this flaw by inserting a specially crafted serialized PHP object into the CacheWarmer cookie.

This vulnerability affects all versions of the Mirasvit extension prior to 1.11.12. A patch addressing the issue was released on May 25, 2026, highlighting the urgency for users to update their systems.

Exploitation Details and Security Implications

The inclusion of CVE-2026-45247 in the KEV catalog was prompted by Sansec’s announcement that any storefront request with a crafted CacheWarmer cookie could exploit this vulnerability. The process involves PHP’s unserialize() function, which is executed without requiring authentication or administrative privileges.

Sansec further highlighted the potential for PHP object injection, which, when combined with existing Magento and dependency classes, can escalate to remote code execution. This discovery underscores the need for heightened vigilance among Magento users.

Current Exploitation Activities and Recommendations

Imperva, a security company owned by Thales, has reported observing malicious activities targeting CVE-2026-45247. The attacks involve serialized PHP object payloads delivered through harmful HTTP requests. These payloads are crafted to trigger object deserialization, ultimately allowing remote execution of arbitrary commands on affected servers.

The primary targets of these attacks are gaming and business websites, with countries like the United States, United Kingdom, France, and Australia being the most affected. Although the perpetrators remain unidentified, the goal appears to be identifying vulnerable Magento systems and verifying the possibility of remote code execution.

Federal Civilian Executive Branch (FCEB) agencies have been instructed to apply the necessary patches by June 6, 2026, to mitigate exploitation risks. Website administrators are advised to scrutinize storefront requests for CacheWarmer cookies with values starting with “CacheWarmer:” followed by a Base64-encoded string, as these may signal exploitation attempts.

In summary, the addition of this Magento vulnerability to CISA’s KEV catalog emphasizes the critical need for patching and vigilant monitoring to protect against potential threats.

The Hacker News Tags:CacheWarmer, CISA, CVE-2026-45247, Cybersecurity, Deserialization, Exploitation, Imperva, Magento, Mirasvit, PHP, RCE, Sansec, Vulnerability, web security

Post navigation

Previous Post: Malicious Code Stealer Deployed via Google Sites
Next Post: Critical VS Code Flaw Enables GitHub Token Theft

Related Posts

Researchers Uncover Batavia Windows Spyware Stealing Documents from Russian Firms Researchers Uncover Batavia Windows Spyware Stealing Documents from Russian Firms The Hacker News
Two CVSS 10.0 Bugs in Red Lion RTUs Could Hand Hackers Full Industrial Control Two CVSS 10.0 Bugs in Red Lion RTUs Could Hand Hackers Full Industrial Control The Hacker News
Google Fixes Android Flaw (CVE-2025-27363) Exploited by Attackers Google Fixes Android Flaw (CVE-2025-27363) Exploited by Attackers The Hacker News
Russian Group EncryptHub Exploits MSC EvilTwin Vulnerability to Deploy Fickle Stealer Malware Russian Group EncryptHub Exploits MSC EvilTwin Vulnerability to Deploy Fickle Stealer Malware The Hacker News
Why 2026 Will be the Year of Machine-Speed Security Why 2026 Will be the Year of Machine-Speed Security The Hacker News
Cryptojacking Campaign Exploits DevOps APIs Using Off-the-Shelf Tools from GitHub Cryptojacking Campaign Exploits DevOps APIs Using Off-the-Shelf Tools from GitHub The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Cisco Alerts on PoC for Critical Unified CM Flaw
  • Critical VS Code Flaw Enables GitHub Token Theft
  • Critical Magento RCE Flaw Added to CISA Vulnerability List
  • Malicious Code Stealer Deployed via Google Sites
  • DoJ Cracks Down on SE Asia Crypto Scams, $3.8M Frozen

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Cisco Alerts on PoC for Critical Unified CM Flaw
  • Critical VS Code Flaw Enables GitHub Token Theft
  • Critical Magento RCE Flaw Added to CISA Vulnerability List
  • Malicious Code Stealer Deployed via Google Sites
  • DoJ Cracks Down on SE Asia Crypto Scams, $3.8M Frozen

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark