Mark RadarMARK RADAR
About
EN
Sign in
Event File FINTECH Security Vulnerabilities

Critical RCE Flaw in Magento Extension Affects More Than 6,000 Online Stores

2 reports · First detected 2026-06-02 · Last active 2026-06-04

Magento and Adobe Commerce merchants commonly use Mirasvit Cache Warmer to prebuild full-page caches and speed up storefront loading. Sansec found that the extension passed user-controlled data to PHP’s unserialize() function, creating an object-injection vulnerability. Unauthenticated attackers could remotely execute code, putting transaction data and control of affected servers at risk.

Sansec discovered the vulnerability on April 24, 2026, and Mirasvit released version 1.11.12 to patch it on May 25. It was designated CVE-2026-45247 the following day and received a CVSS 3.1 score of 9.8. Sansec scanned more than 6,000 stores using Mirasvit extensions. The U.S. Cybersecurity and Infrastructure Security Agency confirmed exploitation on June 3 and added the flaw to its Known Exploited Vulnerabilities catalog, requiring federal agencies to address it by June 6.

All Coverage

2 original reports

The Backstory

The history behind this event
Hackers Hide Payment Skimmer in SVG Files on Magento Stores2026-04-09 · 1 reports · similarity 0.81

Magento, a widely used e-commerce platform, has long been targeted by Magecart groups that compromise online checkout systems to steal payment-card and transaction data. The latest campaign is notable because the attackers disguise skimming code inside an SVG image, a technique designed to evade routine inspection by merchants, security tools and shoppers while keeping the storefront’s payment process apparently functional.

Cybersecurity firm Sansec recently identified a large-scale wave of infections exploiting Magento vulnerabilities. The attackers planted a 1-by-1-pixel SVG file that concealed a payment-data skimmer and presented victims with a fraudulent checkout form. After customers entered their details, the page redirected them to the legitimate checkout, allowing the purchase to proceed normally even though their sensitive transaction information had already been captured.

Mark Radar|MARK RADAR

If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →

All times are in Taipei time (GMT+8)