CVE-2024-34102Active Exploitation(adobe / commerce)

MEDIUMCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch adobe commerce systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution. An attacker could exploit this vulnerability by sending a crafted XML document that references external entities. Exploitation of this issue does not require user interaction.

4.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2024-08-07. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-611

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • commerce
  • commerce_webhooks
  • magento

Threat summary

  • Active exploitation appears in 2 classified signals
  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-03-20); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
commercecommerce_webhooksmagento

6 versions affected across 3 products

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-20: 1Mentions · 2026-03-22: 1Mentions · 2026-03-26: 1Active Exploitation · 2026-03-20: 1Active Exploitation · 2026-03-26: 1Patch / Workaround · 2026-03-20: 1Technical Details · 2026-03-20: 1Technical Details · 2026-03-22: 1Technical Details · 2026-03-26: 103-2003-2203-26
Signal classification2 categories
Active Exploitation
266.7%
General
133.3%
Referenced assets1 URL
Classification over time
DateTotalLabels
2026-03-201
Active Exploitation1
2026-03-221
General1
2026-03-261
Active Exploitation1
Full discourse3 posts
  • Orizon@OrizonCyber
    Active Exploitation

    The attackers are targeting CVE-2024-34102 - a critical RCE flaw patched in June. Payment processors, supply chains, government portals all getting hit. This isn't random script kiddies anymore. When will orgs learn that "it won't happen to us" isn't a security strategy?

    Post summary

    The post highlights that CVE-2024-34102, a critical RCE flaw patched in June, is currently being actively exploited against payment processors, supply chains, and government portals.

    1000036
    7 followersView on X
  • Orizon@OrizonCyber
    Active Exploitation

    PolyShell targets CVE-2024-34102 in Magento 2.4.7 and older. Attackers upload malicious files through XML validation bypass, then execute remote code to steal customer data and payment info. Exploits are live in the wild since June. Still running unpatched stores?

    Post summary

    PolyShell exploits CVE-2024-34102 via an XML validation bypass in Magento 2.4.7 and earlier, with live exploitation active since June that allows remote code execution to steal customer data.

    0000040
    10 followersView on X
  • UNDERCODE TESTING@UndercodeUpdate
    General

    🚨 How a Single Malicious XML Payload Exposed #LG’s API to Remote Code Execution (#CVE-2024-34102) + Video https://undercodetesting.com/how-a-single-malicious-xml-payload-exposed-lgs-api-to-remote-code-execution-cve-2024-34102-video/ Educational Purposes!

    Post summary

    The post references CVE‑2024‑34102 and notes that a single malicious XML payload caused RCE in LG’s API, linking to a video demonstration, but it does not provide code, a patch, or evidence of real‑world exploitation.

    0000030
    412 followersView on X
CPE platform detail59 entries

59 of 59 entries

PartVendorProductVersionTarget SWTarget HW
Appadobecommerce2.4.2--
Appadobecommerce2.4.2--
Appadobecommerce2.4.2--
Appadobecommerce2.4.2--
Appadobecommerce2.4.2--
Appadobecommerce2.4.2--
Appadobecommerce2.4.3--
Appadobecommerce2.4.3--
Appadobecommerce2.4.3--
Appadobecommerce2.4.3--
Appadobecommerce2.4.3--
Appadobecommerce2.4.3--
Appadobecommerce2.4.4--
Appadobecommerce2.4.4--
Appadobecommerce2.4.4--
Appadobecommerce2.4.4--
Appadobecommerce2.4.4--
Appadobecommerce2.4.4--
Appadobecommerce2.4.4--
Appadobecommerce2.4.4--
Appadobecommerce2.4.5--
Appadobecommerce2.4.5--
Appadobecommerce2.4.5--
Appadobecommerce2.4.5--
Appadobecommerce2.4.5--
Appadobecommerce2.4.5--
Appadobecommerce2.4.5--
Appadobecommerce2.4.6--
Appadobecommerce2.4.6--
Appadobecommerce2.4.6--
Appadobecommerce2.4.6--
Appadobecommerce2.4.6--
Appadobecommerce2.4.7--
Appadobecommerce_webhooks---
Appadobemagento2.4.4--
Appadobemagento2.4.4--
Appadobemagento2.4.4--
Appadobemagento2.4.4--
Appadobemagento2.4.4--
Appadobemagento2.4.4--
Appadobemagento2.4.4--
Appadobemagento2.4.4--
Appadobemagento2.4.4--
Appadobemagento2.4.5--
Appadobemagento2.4.5--
Appadobemagento2.4.5--
Appadobemagento2.4.5--
Appadobemagento2.4.5--
Appadobemagento2.4.5--
Appadobemagento2.4.5--
Appadobemagento2.4.5--
Appadobemagento2.4.6--
Appadobemagento2.4.6--
Appadobemagento2.4.6--
Appadobemagento2.4.6--
Appadobemagento2.4.6--
Appadobemagento2.4.6--
Appadobemagento2.4.7--
Appadobemagento2.4.7--

Explore more