Web_Logo
Remote Support
Security Alert: Magento RCE Actively Exploited — Patch Now
Home » Security Alerts  »  Security Alert: Magento RCE Actively Exploited — Patch Now

Security Alert: Magento RCE Actively Exploited — Patch Now

A critical vulnerability in a popular Magento plugin is being actively exploited by attackers worldwide, including in Australia. If your business runs an online store on Magento or Adobe Commerce, this requires urgent attention.

  • What it is: CVE-2026-45247 is a remote code execution (RCE) flaw in the Mirasvit Full Page Cache Warmer plugin for Magento, rated 9.8 out of 10 in severity (critical). It allows an unauthenticated attacker to run arbitrary code on the web server by sending a crafted malicious request.
  • Who is affected: Businesses running Magento 2 or Adobe Commerce with the Mirasvit Cache Warmer plugin installed in versions prior to 1.11.12. Australia is among the most targeted countries in confirmed active attacks.
  • What the risk is: A successful exploit gives an attacker full control of the web server — they could steal customer data, install malware, redirect traffic, or take the store offline.
  • What action is needed: Update the Mirasvit Full Page Cache Warmer plugin to version 1.11.12 or later immediately. If you are unsure whether your store is affected, contact your web developer or hosting provider today.

The US Cybersecurity and Infrastructure Security Agency (CISA) added this vulnerability to its Known Exploited Vulnerabilities Catalog on 3 June 2026. Active exploitation has been confirmed. We recommend treating this as urgent — if you need assistance assessing your e-commerce environment, contact OzComm.