<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>PrestaShop Virtual POS Module (26.8.1 &lt;= Version &lt; 26.9.1) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/prestashop-virtual-pos-module-26.8.1--version--26.9.1/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 09 Oct 2026 14:00:40 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/prestashop-virtual-pos-module-26.8.1--version--26.9.1/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Cryptographic Signature Spoofing in Sipay PrestaShop Virtual POS Module</title><link>https://feed.craftedsignal.io/briefs/2026-10-sipay-pos-spoofing/</link><pubDate>Fri, 09 Oct 2026 14:00:40 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-sipay-pos-spoofing/</guid><description>CVE-2026-86405 describes a critical signature validation flaw in the Sipay PrestaShop Virtual POS Module allowing attackers to spoof transaction integrity checks and manipulate payment requests.</description><content:encoded><![CDATA[<p>CVE-2026-86405 is a high-severity vulnerability within the Sipay Electronic Money and Payment Services Inc. Virtual POS module for the PrestaShop e-commerce platform. The vulnerability exists due to improper verification of cryptographic signatures during the payment processing workflow. Because the module fails to robustly validate the authenticity of signatures, an unauthenticated attacker can perform signature spoofing to bypass integrity checks. This flaw effectively allows unauthorized modification of payment parameters or the simulation of successful payment responses within the application environment. The vulnerability impacts versions of the module ranging from 26.8.1 to 26.9.0. Due to the high CVSS score of 9.8, this flaw represents a significant risk for merchants using the Sipay integration, as it facilitates direct financial manipulation and unauthorized transaction processing.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows attackers to bypass payment integrity checks, leading to unauthorized transaction processing or the manipulation of payment request data. This poses an immediate financial risk to merchants relying on the Sipay Virtual POS module for payment processing, potentially leading to revenue loss and compromised e-commerce site integrity.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade the Sipay Virtual POS Module to version 26.9.1 or later to resolve the improper signature verification logic.</li>
<li>Audit transaction logs for suspicious payment status transitions or inconsistencies between the internal PrestaShop order state and the expected payment provider callback data.</li>
<li>Disable the Sipay Virtual POS integration if patching is not immediately feasible until the vendor-supplied fix can be applied.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>e-commerce</category><category>financial-services</category><category>vulnerability</category><category>signature-spoofing</category></item></channel></rss>