A severe security flaw has been discovered in the Mirasvit Cache Warmer extension used by Magento and Adobe Commerce websites. Identified as CVE-2026-45247, the vulnerability has received a CVSS score of 9.8, reflecting its critical impact. The issue enables remote attackers to execute arbitrary code on vulnerable servers without requiring valid credentials, administrative access, or user interaction. Because the extension is commonly deployed across online stores, a successful attack could result in significant disruption and compromise of e-commerce environments. The vulnerability arises from insecure processing of data contained within a Cache Warmer cookie. The extension uses this cookie to manage cached content for different user sessions, currencies, and customer groups. However, insufficient validation allows attacker-controlled data to be passed to PHP's unserialize() function. This weakness can be exploited to perform a PHP Object Injection attack, which may be combined with existing code components within Magento and related libraries to achieve Remote Code Execution (RCE). As the vulnerable functionality is accessible through normal web requests, attackers can target publicly exposed storefronts with minimal effort. Systems running Mirasvit Cache Warmer versions earlier than 1.11.12 are affected, including installations where the extension is bundled with other Mirasvit products. Organizations should update to the latest patched release as soon as possible. Additional security measures include implementing a web application firewall, monitoring logs for suspicious CacheWarmer cookie activity, and inspecting systems for signs of compromise such as unauthorized files, web shells, or malicious modifications. Due to the lack of authentication requirements and the potential for complete server takeover, prompt remediation is essential to reduce the risk of exploitation and protect sensitive business data.
Researchers have uncovered a targeted cyber espionage campaign, dubbed Operation XENOFISCAL, attributed to the Pakistan-aligned threat group SideCopy. The operation primarily targe...
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2024-21182, a critical vulnerability affecting Oracle WebLogic Server, to its Known Exploited Vulnera...
Dashlane has revealed that it recently detected and mitigated a targeted brute-force attack aimed at a limited number of user accounts. The incident triggered the company's aut...