Cyber & AI intelligence
Wasteland.
Briefs indexed3100
Issues31
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-86405 2026-10-09

CVE-2026-86405: Critical Signature Spoofing Flaw in Sipay PrestaShop Virtual POS Module

"CVE-2026-86405 is a critical (CVSS 9.8) flaw in how Sipay's PrestaShop Virtual POS Module checks cryptographic signatures. Based on its CVSS vector, an attacker could spoof signatures over the network without logging in."

CVE-2026-86405 is a critical (CVSS 9.8) flaw in how Sipay's PrestaShop Virtual POS Module checks cryptographic signatures. Based on its CVSS vector, an attacker could spoof signatures over the network without logging in.

What Is It

CVE-2026-86405 is an improper verification of cryptographic signature vulnerability (CWE-347) in the PrestaShop Virtual POS Module from Sipay Electronic Money and Payment Services Inc. The NVD description says the flaw "allows Signature Spoofing by Improper Validation." The description is brief, but it suggests the module does not properly validate signatures, which could let an attacker present forged signatures that the module accepts as genuine.

The CVE was published on 2026-10-09 by USOM ([email protected]), Turkey's national cyber incident response center. Its NVD status is currently "Deferred."

Why It Matters

USOM rates the flaw CVSS v3.1 9.8 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H:

According to this CVSS assessment, an unauthenticated remote attacker could exploit the flaw with little effort and without any victim action. The affected component is a payment (virtual POS) module, which makes the integrity of signature checks especially important.

Exploitation status: CVE-2026-86405 is not in the CISA Known Exploited Vulnerabilities (KEV) catalog, and the supplied sources do not confirm active exploitation.

What's Vulnerable

The NVD record lists no CPE entries.

Patch Status

According to the vendor-supplied version data, the issue affects versions before 26.9.1, so version 26.9.1 falls outside the affected range. Administrators running PrestaShop with Sipay's Virtual POS Module at version 26.8.1 or later, but below 26.9.1, should upgrade to 26.9.1 or later. They should also check the USOM advisory (TR-26-1287) for any additional vendor guidance.

Because the CVE is not in KEV, CISA has issued no KEV-mandated required action or due date.

Sources