Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2041+ Articles
153+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. CISA Adds Exploited Magento RCE Flaw CVE-2026-45247 to KEV Catalog
CISA Adds Exploited Magento RCE Flaw CVE-2026-45247 to KEV Catalog
NEWS

CISA Adds Exploited Magento RCE Flaw CVE-2026-45247 to KEV Catalog

CISA has added a critical remote code execution vulnerability in the Mirasvit Cache Warmer Magento extension to its Known Exploited Vulnerabilities catalog…

Dylan H.

News Desk

June 4, 2026
2 min read

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-45247 to its Known Exploited Vulnerabilities (KEV) catalog, following confirmed reports of active exploitation targeting Magento e-commerce environments running the Mirasvit Cache Warmer extension.

What Is CVE-2026-45247?

The flaw resides in Mirasvit Cache Warmer, a widely used full-page cache extension for Magento (Adobe Commerce). The vulnerability allows unauthenticated remote attackers to execute arbitrary code on vulnerable server instances, potentially leading to full store compromise, data theft, or deployment of web shells.

CISA's KEV listing indicates the agency has confirmed active exploitation in real-world attacks — not just proof-of-concept demonstrations. Federal agencies under CISA's jurisdiction are required to patch KEV-listed vulnerabilities within mandated deadlines.

Who Is Affected?

Any Magento or Adobe Commerce store running a vulnerable version of the Mirasvit Cache Warmer extension is at risk. Magento powers a significant portion of global e-commerce storefronts, making this vulnerability particularly impactful for retailers handling payment card data and personal customer information.

Site owners who have not applied available security patches should treat this as an emergency remediation priority given the confirmed exploitation activity.

Immediate Steps for Site Owners

  1. Identify vulnerable installs — Audit all Magento instances for Mirasvit Cache Warmer and determine the installed version.
  2. Apply the patch immediately — Check the Mirasvit vendor portal and Magento Marketplace for updated extension versions that address CVE-2026-45247.
  3. Review web server logs — Look for anomalous POST requests, unexpected admin account creation, or unfamiliar file uploads that may indicate prior compromise.
  4. Enable WAF rules — Web application firewall rules targeting this CVE can help block exploitation attempts while patching is underway.
  5. Rotate credentials — If compromise is suspected, rotate admin credentials, API keys, and payment gateway secrets immediately.

Broader Context: Magento Attacks in 2026

Magento continues to be a high-value target for cybercriminals due to the payment card data and personal information stored on e-commerce platforms. Skimming attacks (Magecart-style) and RCE exploits against Magento extensions have been a persistent threat vector throughout 2026.

CISA's KEV catalog addition serves as a clear signal that threat actors are actively leveraging CVE-2026-45247 in campaigns against live storefronts — merchants operating unpatched sites face serious financial and regulatory exposure.

References

  • CISA KEV Catalog
  • The Hacker News Coverage
#CVE#Vulnerability#CISA#Magento#RCE#KEV

Related Articles

Langflow RCE Exploited to Deploy Monero Miner on Exposed AI App Endpoints

Threat actors are actively weaponizing CVE-2026-33017, a critical unauthenticated RCE flaw in Langflow, to deploy a Monero miner via the lambsys...

6 min read

First-Ever Exploitation of PTC Windchill Vulnerability Discovered in the Wild

CISA has added CVE-2026-12569, a remote code execution flaw in PTC Windchill, to its Known Exploited Vulnerabilities catalog after confirming active...

3 min read

Drupal Core SQL Injection Bug Actively Exploited, Added to CISA KEV

CISA has added CVE-2026-9082, a SQL injection vulnerability in Drupal Core, to its Known Exploited Vulnerabilities catalog following confirmed in-the-wild...

4 min read
Back to all News