<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Cisa-Kev on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/cisa-kev/</link><description>Recent content in Cisa-Kev on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Wed, 03 Jun 2026 16:30:00 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/cisa-kev/index.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-45247: Magento RCE Flaw Added to CISA KEV</title><link>https://zxcloudsecurity.co.uk/posts/cisa-kev-magento-rce-cve-2026-45247-mirasvit-cache-warmer/</link><pubDate>Wed, 03 Jun 2026 16:30:00 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/cisa-kev-magento-rce-cve-2026-45247-mirasvit-cache-warmer/</guid><description>CISA adds CVE-2026-45247, a CVSS 9.8 RCE flaw in the Mirasvit Cache Warmer Magento extension, to its KEV catalogue amid active exploitation.</description><content:encoded><![CDATA[<p>🔴 <strong>Critical</strong>  |  <strong>Source:</strong> <a href="https://thehackernews.com/2026/06/cisa-adds-exploited-magento-rce-flaw.html">The Hacker News</a></p>
<hr>
<p>CISA has added CVE-2026-45247, a critical remote code execution vulnerability in the Mirasvit Cache Warmer Magento extension, to its Known Exploited Vulnerabilities catalogue following confirmed active exploitation. The flaw, scoring 9.8 on the CVSS scale, stems from insecure deserialisation of untrusted data, allowing an attacker to execute arbitrary code on affected systems. Any organisation running this extension on their Magento e-commerce platform should treat this as an urgent remediation priority.</p>
<blockquote>
<p><strong>Architect&rsquo;s Take:</strong> Audit your Magento deployments immediately for the Mirasvit Cache Warmer extension and apply the vendor patch or remove the extension if no patch is available. Given active exploitation, also review web application firewall rules and inspect recent server logs for anomalous deserialisation payloads or unexpected outbound connections.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://thehackernews.com/2026/06/cisa-adds-exploited-magento-rce-flaw.html">CISA Adds Exploited Magento RCE Flaw CVE-2026-45247 to KEV Catalog</a></p>
]]></content:encoded></item><item><title>CVE-2026-45247: Mirasvit Cache Warmer RCE Flaw</title><link>https://zxcloudsecurity.co.uk/posts/cve-2026-45247-mirasvit-full-page-cache-warmer-rce-deserialization/</link><pubDate>Wed, 03 Jun 2026 00:00:00 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/cve-2026-45247-mirasvit-full-page-cache-warmer-rce-deserialization/</guid><description>CVE-2026-45247 allows unauthenticated RCE via PHP deserialisation in Mirasvit Full Page Cache Warmer. Actively exploited — patch immediately.</description><content:encoded><![CDATA[<p>🔴 <strong>Critical</strong>  |  <strong>Source:</strong> <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">CISA Known Exploited Vulnerabilities</a></p>
<hr>
<p>A critical vulnerability in the Mirasvit Full Page Cache Warmer extension for Magento/Adobe Commerce allows unauthenticated attackers to execute arbitrary code on affected servers. The flaw stems from unsafe deserialisation of a crafted PHP object passed via the CacheWarmer cookie, requiring no login or prior access. This vulnerability is actively being exploited in the wild, confirmed by CISA&rsquo;s inclusion in its Known Exploited Vulnerabilities catalogue.</p>
<blockquote>
<p><strong>Architect&rsquo;s Take:</strong> Identify any Magento or Adobe Commerce instances running the Mirasvit Full Page Cache Warmer extension and apply the vendor patch immediately ahead of the 6 June 2026 remediation deadline. Where patching is not immediately possible, implement a WAF rule to inspect and block malicious serialised PHP objects in the CacheWarmer cookie as an interim control.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">CVE-2026-45247: Mirasvit Mirasvit Full Page Cache Warmer</a></p>
]]></content:encoded></item><item><title>Oracle WebLogic CVE-2024-21182 Actively Exploited</title><link>https://zxcloudsecurity.co.uk/posts/oracle-weblogic-cve-2024-21182-kev-active-exploitation/</link><pubDate>Tue, 02 Jun 2026 18:14:42 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/oracle-weblogic-cve-2024-21182-kev-active-exploitation/</guid><description>CISA adds CVE-2024-21182 to KEV catalogue after active exploitation. The CVSS 7.5 flaw lets unauthenticated attackers take control of Oracle WebLogic serve</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://thehackernews.com/2026/06/oracle-weblogic-cve-2024-21182-added-to.html">The Hacker News</a></p>
<hr>
<p>A high-severity vulnerability in Oracle WebLogic Server (CVE-2024-21182) has been added to CISA&rsquo;s Known Exploited Vulnerabilities catalogue following confirmed active exploitation in the wild. The flaw allows an unauthenticated attacker with network access to take full control of affected servers without any credentials. Any organisation running Oracle WebLogic in cloud or on-premises environments should treat this as an urgent remediation priority.</p>
<blockquote>
<p><strong>Architect&rsquo;s Take:</strong> Audit your cloud environments immediately for internet-exposed or network-accessible WebLogic instances and apply Oracle&rsquo;s patch from the January 2024 Critical Patch Update without delay. As an interim control, restrict network access to WebLogic admin ports using security groups or firewall rules, and consider placing instances behind a WAF or application gateway.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://thehackernews.com/2026/06/oracle-weblogic-cve-2024-21182-added-to.html">Oracle WebLogic CVE-2024-21182 Added to KEV Catalog After Active Exploitation</a></p>
]]></content:encoded></item></channel></rss>