Mirasvit Full Page Cache Warmer contains a deserialization of untrusted data vulnerability that could allow unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the CacheWarmer cookie.
The Mirasvit Full Page Cache Warmer extension for Magento 2 passes a client-supplied cookie value directly to PHP's native unserialize() function without restricting which classes may be instantiated. An unauthenticated attacker can send a single crafted HTTP request to any storefront page and achieve remote code execution on the server. All versions of the extension before 1.11.12 are affected, including installations bundled with other Mirasvit packages.
The extension pre-populates Magento's full-page cache by crawling storefront pages with session state packed into a CacheWarmer cookie. A plugin reads that cookie on every storefront request and passes part of its value to PHP's native unserialize() without a class allowlist. This is a textbook CWE-502 (Deserialization of Untrusted Data) condition: because PHP reconstructs arbitrary class instances from the supplied byte stream, an attacker who controls the cookie value controls which objects are instantiated and how their magic methods execute during deserialization.
An attacker sends a standard HTTP GET or POST request to any Magento storefront page, setting the CacheWarmer cookie to a base64-encoded, serialized PHP gadget-chain payload built from classes already present in Magento and its dependencies. No authentication, admin session, or configuration change is required. Successful exploitation gives the attacker unauthenticated remote code execution on the server, with the ability to plant webshells, backdoors, or other malware in web-accessible directories.
This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.
If Mirasvit Full Page Cache Warmer runs inside your authorization boundary, CVE-2026-45247 affects your FedRAMP authorization directly. The vulnerability is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog with a remediation deadline of June 6, 2026, a date that has already passed. An unpatched KEV inside your boundary is an assessor finding; an overdue one is already visible to your assessor and sponsoring agency. Remediate now or formally document your mitigation and the delay.
Knox does not patch your software. Remediating Mirasvit Full Page Cache Warmer is your responsibility under the FedRAMP shared-responsibility model. What Knox provides is the pre-authorized, single-tenant boundary to remediate within, plus Knox's automated continuous monitoring platform and audit-artifact coverage that document the fix for your next assessment. Applying the patch is yours to own; maintaining a defensible compliance posture while you do it is not something you have to manage alone.
Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues on a continuous basis. For a vulnerability like CVE-2026-45247, that means exposure surfaces during ongoing monitoring rather than only when an assessor flags it at review time, giving you a narrower window of undetected risk.
Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.
If CVE-2026-45247 remains unremediated, it is already a Plan of Action and Milestones (POA&M) item. A growing POA&M list is precisely what turns a routine continuous-monitoring review into a difficult agency conversation. Closing the finding out and documenting why the deadline was missed is what keeps your authorization intact and the agency relationship on solid ground.
Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.









_Horizontal_RGB.png)








