SECURITYTHE HACKER NEWS
CISA Adds Exploited Magento RCE Flaw CVE-2026-45247 to KEV Catalog
CISA added a critical remote code execution (RCE) vulnerability in Mirasvit Cache Warmer, a Magento extension, to its KEV catalog due to active exploitation. The flaw, CVE-2026-45247 with a CVSS score of 9.8, involves deserialization of untrusted data.
Mentioned
Related Signal
Adjacent reporting
- Microsoft Patches SharePoint RCE Flaw CVE-2026-45659 Across Server Versions
- MetInfo CMS CVE-2026-29014 Exploited for Remote Code Execution Attacks
- Critical Unpatched Flaw Leaves Hugging Face LeRobot Open to Unauthenticated RCE
- Marimo RCE Flaw CVE-2026-39987 Exploited Within 10 Hours of Disclosure
- Ivanti EPMM CVE-2026-6973 RCE Under Active Exploitation Grants Admin-Level Access
- SGLang CVE-2026-5760 (CVSS 9.8) Enables RCE via Malicious GGUF Model Files