Executive brief
Mirasvit Full Page Cache Warmer is a performance optimization tool for Magento e-commerce websites. A critical security flaw allows unauthenticated attackers to take full control of the web server by sending a specially crafted browser cookie. This could lead to the theft of customer data, site defacement, or complete service disruption, and there are reports that this vulnerability is being actively exploited in the wild.
Technical details
A PHP object injection vulnerability exists in Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12. The flaw stems from an unrestricted call to the native PHP unserialize() function on data provided via the 'CacheWarmer' HTTP cookie. An unauthenticated remote attacker can exploit this by providing a malicious serialized PHP object. When combined with existing gadget chains in Magento or its dependencies, this leads to arbitrary remote code execution (RCE) on the underlying server. This vulnerability has been reported as exploited in the wild.
Affected products
- Mirasvit Full Page Cache Warmer for Magento 2 before 1.11.12
Timeline
- 2026-05-26: disclosed: Initial disclosure and NVD entry creation
- 2026-06-03: advisory: Publication of vulnerability details
- 2026-06-03: exploited: Reported as exploited in the wild
- 2026-05-26: patched: Fixed in version 1.11.12