{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/signature-spoofing/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:sipay:prestashop_virtual_pos_module:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-86405"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["PrestaShop Virtual POS Module (26.8.1 \u003c= version \u003c 26.9.1)"],"_cs_severities":["critical"],"_cs_tags":["e-commerce","financial-services","vulnerability","signature-spoofing"],"_cs_type":"advisory","_cs_vendors":["Sipay"],"content_html":"\u003cp\u003eCVE-2026-86405 is a high-severity vulnerability within the Sipay Electronic Money and Payment Services Inc. Virtual POS module for the PrestaShop e-commerce platform. The vulnerability exists due to improper verification of cryptographic signatures during the payment processing workflow. Because the module fails to robustly validate the authenticity of signatures, an unauthenticated attacker can perform signature spoofing to bypass integrity checks. This flaw effectively allows unauthorized modification of payment parameters or the simulation of successful payment responses within the application environment. The vulnerability impacts versions of the module ranging from 26.8.1 to 26.9.0. Due to the high CVSS score of 9.8, this flaw represents a significant risk for merchants using the Sipay integration, as it facilitates direct financial manipulation and unauthorized transaction processing.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows attackers to bypass payment integrity checks, leading to unauthorized transaction processing or the manipulation of payment request data. This poses an immediate financial risk to merchants relying on the Sipay Virtual POS module for payment processing, potentially leading to revenue loss and compromised e-commerce site integrity.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the Sipay Virtual POS Module to version 26.9.1 or later to resolve the improper signature verification logic.\u003c/li\u003e\n\u003cli\u003eAudit transaction logs for suspicious payment status transitions or inconsistencies between the internal PrestaShop order state and the expected payment provider callback data.\u003c/li\u003e\n\u003cli\u003eDisable the Sipay Virtual POS integration if patching is not immediately feasible until the vendor-supplied fix can be applied.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-09T14:00:40Z","date_published":"2026-10-09T14:00:40Z","id":"https://feed.craftedsignal.io/briefs/2026-10-sipay-pos-spoofing/","summary":"CVE-2026-86405 describes a critical signature validation flaw in the Sipay PrestaShop Virtual POS Module allowing attackers to spoof transaction integrity checks and manipulate payment requests.","title":"Cryptographic Signature Spoofing in Sipay PrestaShop Virtual POS Module","url":"https://feed.craftedsignal.io/briefs/2026-10-sipay-pos-spoofing/"}],"language":"en","title":"CraftedSignal Threat Feed - Signature-Spoofing","version":"https://jsonfeed.org/version/1.1"}