← Global Threat Landscape

CVE-2026-45247

CWE-502

Critical

95.2

RPS

Description

Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that allows unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the CacheWarmer cookie. Attackers can exploit the unrestricted call to PHP's native unserialize() function combined with gadget chains available in Magento and its dependencies to execute arbitrary code on the server.

Source: NVD

Signals

CVSS
9.8
Critical · v3.1
EPSS
2.08%
Probability of exploitation in the next 30 days (FIRST)
CISA KEV
In CISA KEV since Jun 2026
Fix commit
No known fix commit
Sources: MoreFixes, FreshFixes
Weakness
CWE-502
Published
26 May 2026
Last modified 24 Jul 2026

How to read these signals: RPS · EPSS · CISA KEV · Data sources

Get this score from the API

curl -H "Authorization: Bearer dsec_live_xxxxxxxx" \
  https://api.intelligence.devsecure.io/api/v1/rps/CVE-2026-45247

Replace the placeholder with your key. Get a free API key or rank your own CVEs.

Data as of 7 Oct 2026, 05:16 UK time

CVE-2026-45247 · RPS 95.2 · DevSecure Intelligence