Critical Analysis: CVE-2026-45247 - Mirasvit Full Page Cache Warmer Deserialization of Untrusted... — June 4, 2026
Published 04 Jun 2026 · vulnerability management, CVE analysis, threat intelligence, security operations, cybersecurity news
Initial Discovery and Context Just yesterday, June 4, 2026, the cybersecurity community received notification of CVE-2026-45247, detailing a critical deserialization of untrusted data vulnerability within Mirasvit's Full Page Cache Warmer extension for Magento. As a senior analyst, when I see "deserialization of untrusted data," my ears immediately perk up. This isn't some niche bug; it's a known, powerful exploit primitive that often leads directly to remote code execution (RCE). Mirasvit is a significant player in the Magento ecosystem, providing extensions that handle crucial performance aspects for e-commerce sites. Their Full Page Cache Warmer is designed to intelligently pre-load cache for pages, improving load times for customers. This means it's often deployed on high-traffic, public-facing Magento instances, making it a prime target. The vulnerability affects Mirasvit Full Page