Desert Forge IT — Arizona IT · Field-tested tools & guidesFree consult →

Adobe Commerce / Magento Exploited CVEs 2026: CVE-2026-75650 (CVSS 10), CVE-2026-71362, Mirasvit Cache Warmer

Critical CVE-2026-75650, CVE-2026-71362, CVE-2026-45247 — Online stores on Adobe Commerce and Magento Open Source face three exploited flaws: a CVSS 10 template-injection RCE, an authorization bypass, and an unauthenticated RCE in the popular Mirasvit Cache Warmer extension. Patches and card-skimmer checks.

Published 2026-10-08 · Last updated 2026-10-08

TL;DR: Magento stores are a constant target because a compromise means stolen card numbers. Three exploited bugs this summer: CVE-2026-75650, a CVSS 10 template-engine injection giving code execution with no user interaction (needs the APSB26-146 hotfix); CVE-2026-71362, an authorization bypass (fixed in the August 2026 releases); and CVE-2026-45247, an unauthenticated RCE through a cookie in Mirasvit Full Page Cache Warmer before 1.11.12.

CVE-2026-75650Template engine injection → arbitrary code execution, scope changed. CVSS 10. Fixed by the APSB26-146 hotfix. KEV 2026-09-08
CVE-2026-71362Incorrect authorization → privilege escalation. CVSS 9.1. Fixed in the 2026-aug releases (e.g. 2.4.8-2026-aug). KEV 2026-09-24
CVE-2026-45247Mirasvit Full Page Cache Warmer < 1.11.12: PHP object injection via the CacheWarmer cookie → unauthenticated RCE. CVSS 9.8. KEV 2026-06-03
AffectedAdobe Commerce 2.4.4–2.4.9, Commerce B2B, Magento Open Source 2.4.6–2.4.9

The three bugs

  • CVE-2026-75650 (CVSS 10): improper neutralisation of special elements in a template engine lets an attacker get their input evaluated as template code, leading to arbitrary code execution. Adobe notes no user interaction is required and the scope is changed. Even the August 2026 release builds are listed as affected; you need the separate hotfix from bulletin APSB26-146 (referenced in the CVE as the “Hotfix for CVE-2026-7565”).
  • CVE-2026-71362 (CVSS 9.1): incorrect authorization lets an attacker reach sensitive resources with elevated access. Fixed in the August 2026 security releases.
  • CVE-2026-45247 (CVSS 9.8): the third-party Mirasvit Full Page Cache Warmer extension passed the CacheWarmer cookie straight to PHP’s unserialize(). Combined with gadget chains in Magento’s own dependencies, that’s unauthenticated code execution with a single request.

Am I affected?

bin/magento --version
composer show magento/product-community-edition magento/product-enterprise-edition 2>/dev/null | grep versions
composer show mirasvit/module-cache-warmer 2>/dev/null | grep versions

You’re exposed to CVE-2026-71362 if you’re on any build older than the -2026-aug release for your line, and to CVE-2026-75650 unless the APSB26-146 hotfix is applied. Any Mirasvit Cache Warmer below 1.11.12 is exposed to CVE-2026-45247.

How to patch

  1. Upgrade to the August 2026 (or later) security release for your line, e.g. 2.4.8-2026-aug, via Composer.
  2. Apply the APSB26-146 hotfix per Adobe’s instructions (Quality Patches Tool or the provided patch file), then run bin/magento setup:upgrade and clear caches.
  3. Update Mirasvit Cache Warmer: composer require mirasvit/module-cache-warmer:^1.11.12, or disable the module if you can’t.
  4. Adobe Commerce on Cloud: Adobe applies some fixes, but check the bulletin; many require you to deploy.

Check for skimmers and backdoors

  • Look for injected JavaScript in core_config_data (design/head/includes, footer), CMS blocks, and theme templates. That’s where card skimmers hide:
    SELECT path, value FROM core_config_data WHERE value LIKE '%<script%';
  • Check for admin users you didn’t create: SELECT username, email, created FROM admin_user;
  • Scan for new PHP files in pub/media, pub/static and var/. Sansec’s free eComscan is built for exactly this.
  • If you find a skimmer, you may have PCI notification obligations. Talk to your payment processor.

Sources

← Back to Knowledge Base

Want this handled for you?

Desert Forge IT patches, monitors, and backs up servers and networks for Phoenix-area businesses. We track advisories like this one so you don’t have to. Get a free consult and we’ll tell you what you’re exposed to.

Get a free security check →  ·  More security advisories