🔴
CISA KEV Alert — Active Real-World Exploitation Confirmed
This vulnerability is in the CISA Known Exploited Vulnerabilities catalog and is being actively exploited right now.
Mirasvit Full Page Cache Warmer RCE Active Exploitation (CVE-2026-45247) | MSSP Advisory
Critical🔴 KEV ALERTConfirmed
DateJune 4, 2026
CVECVE-2026-45247
CVSS Score9.8
Affectedfull_page_cache_warmer
Risk Assessment
Client Exposure:High
Briefing Priority:Immediate
Barrier to Entry:Low
📋Executive Summary
CISA added CVE-2026-45247 to its Known Exploited Vulnerabilities catalog on June 3, a CVSS 9.8 flaw in the Mirasvit Full Page Cache Warmer extension for Magento and Adobe Commerce. The vulnerability requires no authentication and allows remote code execution by injecting malicious base64 encoded payloads into the CacheWarmer HTTP cookie, giving attackers full administrative control over the affected server. Sansec first reported active exploitation on May 26, and CISA set a federal remediation deadline of June 6.
⚠️Why It Matters for MSSPs
If you manage any e-commerce clients running Magento or Adobe Commerce, you need to know right now whether Mirasvit Cache Warmer is installed in their environment, because an unauthenticated attacker can already be executing code and skimming payment credentials without triggering a login event. Your own stack exposure is lower here unless you use Magento internally, but your advisory obligation is immediate and direct because 20 percent of U.S. retailers run this platform and your clients almost certainly include merchants. Silence on this one is a contract problem waiting to happen.
✅Recommended Action
Audit every client environment today for the Mirasvit Full Page Cache Warmer extension, push an emergency patch to version 1.11.12, then send each affected client a written advisory documenting when the patch was applied and what log review was performed to rule out prior compromise.
🔒Get your first advisory free →
Partner content — get access free
The recommended action is included in your white-labeled advisory — ready to send to clients under your name.
🏷️Threat Category
Vulnerability Disclosure
Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.