Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

1371+ Articles
150+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. CISA Adds Exploited Magento RCE Flaw CVE-2026-45247 to KEV Catalog
CISA Adds Exploited Magento RCE Flaw CVE-2026-45247 to KEV Catalog
NEWS

CISA Adds Exploited Magento RCE Flaw CVE-2026-45247 to KEV Catalog

CISA has added a critical remote code execution vulnerability in the Mirasvit Cache Warmer Magento extension to its Known Exploited Vulnerabilities catalog…

Dylan H.

News Desk

June 4, 2026
2 min read

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-45247 to its Known Exploited Vulnerabilities (KEV) catalog, following confirmed reports of active exploitation targeting Magento e-commerce environments running the Mirasvit Cache Warmer extension.

What Is CVE-2026-45247?

The flaw resides in Mirasvit Cache Warmer, a widely used full-page cache extension for Magento (Adobe Commerce). The vulnerability allows unauthenticated remote attackers to execute arbitrary code on vulnerable server instances, potentially leading to full store compromise, data theft, or deployment of web shells.

CISA's KEV listing indicates the agency has confirmed active exploitation in real-world attacks — not just proof-of-concept demonstrations. Federal agencies under CISA's jurisdiction are required to patch KEV-listed vulnerabilities within mandated deadlines.

Who Is Affected?

Any Magento or Adobe Commerce store running a vulnerable version of the Mirasvit Cache Warmer extension is at risk. Magento powers a significant portion of global e-commerce storefronts, making this vulnerability particularly impactful for retailers handling payment card data and personal customer information.

Site owners who have not applied available security patches should treat this as an emergency remediation priority given the confirmed exploitation activity.

Immediate Steps for Site Owners

  1. Identify vulnerable installs — Audit all Magento instances for Mirasvit Cache Warmer and determine the installed version.
  2. Apply the patch immediately — Check the Mirasvit vendor portal and Magento Marketplace for updated extension versions that address CVE-2026-45247.
  3. Review web server logs — Look for anomalous POST requests, unexpected admin account creation, or unfamiliar file uploads that may indicate prior compromise.
  4. Enable WAF rules — Web application firewall rules targeting this CVE can help block exploitation attempts while patching is underway.
  5. Rotate credentials — If compromise is suspected, rotate admin credentials, API keys, and payment gateway secrets immediately.

Broader Context: Magento Attacks in 2026

Magento continues to be a high-value target for cybercriminals due to the payment card data and personal information stored on e-commerce platforms. Skimming attacks (Magecart-style) and RCE exploits against Magento extensions have been a persistent threat vector throughout 2026.

CISA's KEV catalog addition serves as a clear signal that threat actors are actively leveraging CVE-2026-45247 in campaigns against live storefronts — merchants operating unpatched sites face serious financial and regulatory exposure.

References

  • CISA KEV Catalog
  • The Hacker News Coverage
#CVE#Vulnerability#CISA#Magento#RCE#KEV

Related Articles

Drupal Core SQL Injection Bug Actively Exploited, Added to CISA KEV

CISA has added CVE-2026-9082, a SQL injection vulnerability in Drupal Core, to its Known Exploited Vulnerabilities catalog following confirmed in-the-wild...

4 min read

CISA Adds Actively Exploited Linux Root Access Bug

The U.S. Cybersecurity and Infrastructure Security Agency has added CVE-2026-31431, a Linux kernel privilege escalation flaw enabling root access, to its...

4 min read

CISA: Hackers Now Exploit SolarWinds Serv-U Flaw to Crash Servers

CISA added a high-severity SolarWinds Serv-U flaw to its KEV catalog after confirming attackers are actively exploiting it to crash file transfer servers.

5 min read
Back to all News