A critical unauthenticated XXE (XML External Entity) vulnerability has been discovered in Adobe Commerce and Magento, identified as CVE-2024-34102. This flaw, assigned a CVSS score of 9.8, is due to improper restriction of XML external entity references. The vulnerability allows attackers to execute arbitrary code by sending a crafted XML document that references external entities. Exploiting this issue does not require user interaction, and the vulnerability is actively being exploited in attacks.