<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Cve-2026-45247 on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/cve-2026-45247/</link><description>Recent content in Cve-2026-45247 on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Wed, 03 Jun 2026 16:30:00 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/cve-2026-45247/index.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-45247: Magento RCE Flaw Added to CISA KEV</title><link>https://zxcloudsecurity.co.uk/posts/cisa-kev-magento-rce-cve-2026-45247-mirasvit-cache-warmer/</link><pubDate>Wed, 03 Jun 2026 16:30:00 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/cisa-kev-magento-rce-cve-2026-45247-mirasvit-cache-warmer/</guid><description>CISA adds CVE-2026-45247, a CVSS 9.8 RCE flaw in the Mirasvit Cache Warmer Magento extension, to its KEV catalogue amid active exploitation.</description><content:encoded><![CDATA[<p>🔴 <strong>Critical</strong>  |  <strong>Source:</strong> <a href="https://thehackernews.com/2026/06/cisa-adds-exploited-magento-rce-flaw.html">The Hacker News</a></p>
<hr>
<p>CISA has added CVE-2026-45247, a critical remote code execution vulnerability in the Mirasvit Cache Warmer Magento extension, to its Known Exploited Vulnerabilities catalogue following confirmed active exploitation. The flaw, scoring 9.8 on the CVSS scale, stems from insecure deserialisation of untrusted data, allowing an attacker to execute arbitrary code on affected systems. Any organisation running this extension on their Magento e-commerce platform should treat this as an urgent remediation priority.</p>
<blockquote>
<p><strong>Architect&rsquo;s Take:</strong> Audit your Magento deployments immediately for the Mirasvit Cache Warmer extension and apply the vendor patch or remove the extension if no patch is available. Given active exploitation, also review web application firewall rules and inspect recent server logs for anomalous deserialisation payloads or unexpected outbound connections.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://thehackernews.com/2026/06/cisa-adds-exploited-magento-rce-flaw.html">CISA Adds Exploited Magento RCE Flaw CVE-2026-45247 to KEV Catalog</a></p>
]]></content:encoded></item><item><title>CVE-2026-45247: Mirasvit Cache Warmer RCE Flaw</title><link>https://zxcloudsecurity.co.uk/posts/cve-2026-45247-mirasvit-full-page-cache-warmer-rce-deserialization/</link><pubDate>Wed, 03 Jun 2026 00:00:00 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/cve-2026-45247-mirasvit-full-page-cache-warmer-rce-deserialization/</guid><description>CVE-2026-45247 allows unauthenticated RCE via PHP deserialisation in Mirasvit Full Page Cache Warmer. Actively exploited — patch immediately.</description><content:encoded><![CDATA[<p>🔴 <strong>Critical</strong>  |  <strong>Source:</strong> <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">CISA Known Exploited Vulnerabilities</a></p>
<hr>
<p>A critical vulnerability in the Mirasvit Full Page Cache Warmer extension for Magento/Adobe Commerce allows unauthenticated attackers to execute arbitrary code on affected servers. The flaw stems from unsafe deserialisation of a crafted PHP object passed via the CacheWarmer cookie, requiring no login or prior access. This vulnerability is actively being exploited in the wild, confirmed by CISA&rsquo;s inclusion in its Known Exploited Vulnerabilities catalogue.</p>
<blockquote>
<p><strong>Architect&rsquo;s Take:</strong> Identify any Magento or Adobe Commerce instances running the Mirasvit Full Page Cache Warmer extension and apply the vendor patch immediately ahead of the 6 June 2026 remediation deadline. Where patching is not immediately possible, implement a WAF rule to inspect and block malicious serialised PHP objects in the CacheWarmer cookie as an interim control.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">CVE-2026-45247: Mirasvit Mirasvit Full Page Cache Warmer</a></p>
]]></content:encoded></item></channel></rss>