CVE-2026-45247
Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data Vulnerability
⚠ KEVEPSS 6.1%
Description
Mirasvit Full Page Cache Warmer contains a deserialization of untrusted data vulnerability that could allow unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the CacheWarmer cookie.
How to fix CVE-2026-45247
No package mapping is available — consult the references below for vendor-specific guidance.
Is CVE-2026-45247 being exploited?
Yes — CVE-2026-45247 is on the CISA Known Exploited Vulnerabilities (KEV) catalog. Patch immediately.
Affected packages (0)
No package mapping in OSV.