Incident6,000 Stores, One Cookie: The Mirasvit RCE Breakdown
What Happened An unauthenticated attacker can execute arbitrary PHP code on Magento stores running the Mirasvit Cache Warmer extension by sending a malicious cookie. CVE-2026-45247 , a PHP object inje














