Critical CVE-2026-75650, CVE-2026-71362, CVE-2026-45247 — Online stores on Adobe Commerce and Magento Open Source face three exploited flaws: a CVSS 10 template-injection RCE, an authorization bypass, and an unauthenticated RCE in the popular Mirasvit Cache Warmer extension. Patches and card-skimmer checks.
Published 2026-10-08 · Last updated 2026-10-08
TL;DR: Magento stores are a constant target because a compromise means stolen card numbers. Three exploited bugs this summer: CVE-2026-75650, a CVSS 10 template-engine injection giving code execution with no user interaction (needs the APSB26-146 hotfix); CVE-2026-71362, an authorization bypass (fixed in the August 2026 releases); and CVE-2026-45247, an unauthenticated RCE through a cookie in Mirasvit Full Page Cache Warmer before 1.11.12.
| CVE-2026-75650 | Template engine injection → arbitrary code execution, scope changed. CVSS 10. Fixed by the APSB26-146 hotfix. KEV 2026-09-08 |
|---|---|
| CVE-2026-71362 | Incorrect authorization → privilege escalation. CVSS 9.1. Fixed in the 2026-aug releases (e.g. 2.4.8-2026-aug). KEV 2026-09-24 |
| CVE-2026-45247 | Mirasvit Full Page Cache Warmer < 1.11.12: PHP object injection via the CacheWarmer cookie → unauthenticated RCE. CVSS 9.8. KEV 2026-06-03 |
| Affected | Adobe Commerce 2.4.4–2.4.9, Commerce B2B, Magento Open Source 2.4.6–2.4.9 |
CacheWarmer cookie straight to PHP’s unserialize(). Combined with gadget chains in Magento’s own dependencies, that’s unauthenticated code execution with a single request.bin/magento --version
composer show magento/product-community-edition magento/product-enterprise-edition 2>/dev/null | grep versions
composer show mirasvit/module-cache-warmer 2>/dev/null | grep versions
You’re exposed to CVE-2026-71362 if you’re on any build older than the -2026-aug release for your line, and to CVE-2026-75650 unless the APSB26-146 hotfix is applied. Any Mirasvit Cache Warmer below 1.11.12 is exposed to CVE-2026-45247.
bin/magento setup:upgrade and clear caches.composer require mirasvit/module-cache-warmer:^1.11.12, or disable the module if you can’t.core_config_data (design/head/includes, footer), CMS blocks, and theme templates. That’s where card skimmers hide:
SELECT path, value FROM core_config_data WHERE value LIKE '%<script%';SELECT username, email, created FROM admin_user;pub/media, pub/static and var/. Sansec’s free eComscan is built for exactly this.Desert Forge IT patches, monitors, and backs up servers and networks for Phoenix-area businesses. We track advisories like this one so you don’t have to. Get a free consult and we’ll tell you what you’re exposed to.