๐๐ฟ๐ถ๐๐ถ๐ฐ๐ฎ๐น ๐ ๐ฎ๐ด๐ฒ๐ป๐๐ผ ๐ฆ๐ฒ๐ฐ๐๐ฟ๐ถ๐๐ ๐๐น๐ฒ๐ฟ๐: ๐๐ ๐๐ผ๐๐ฟ ๐๐๐ผ๐ฟ๐ฒ ๐ฝ๐ฟ๐ผ๐๐ฒ๐ฐ๐๐ฒ๐ฑ?
In uitvoering
Scheduled on 27.05.2026
Security researchers at Sansec have uncovered a critical vulnerability in the popular Mirasvit Cache Warmer extension for Magento Open Source. The flaw allows unauthenticated remote code execution (RCE) through a specially crafted cookie on any storefront page.
The vulnerability, tracked as CVE-2026-45247 and rated 9.8 Critical, affects all Mirasvit Cache Warmer versions before 1.11.12.
๐ช๐ต๐ ๐๐ต๐ถ๐ ๐บ๐ฎ๐๐๐ฒ๐ฟ๐ ๐
Third-party Magento extensions can significantly improve performance and functionality, but when left unpatched or poorly maintained, they may also introduce serious security risks, including:
๐ธ Remote Code Execution (RCE)
๐ธ SQL Injection
๐ธ Cross-Site Scripting (XSS)
๐ธ Malware & Backdoor Injections
๐ธ Data Leaks
๐ช๐ต๐ฎ๐ ๐๐ผ๐ ๐๐ต๐ผ๐๐น๐ฑ ๐ฑ๐ผ ๐ถ๐บ๐บ๐ฒ๐ฑ๐ถ๐ฎ๐๐ฒ๐น๐:
1๏ธโฃ Check whether your Magento environment is running the Mirasvit Cache Warmer extension
2๏ธโฃ Update to version 1.11.12 or later immediately
3๏ธโฃ Review your logs for suspicious CacheWarmer cookie activity
4๏ธโฃ Scan your environment for potential compromise or malicious PHP files
At Hosted Power, we strongly believe that high-performance Magento hosting should also mean enterprise-grade security. Thatโs why we continuously monitor infrastructure, support proactive patch management and help Magento merchants keep their environments secure, scalable and stable.
๐ Read the full Sansec advisory here:
https://lnkd.in/eF23As9a
Gerelateerde servers / diensten:
Magento servers