Mmastodon TechnologyCybersecurity first seen 10 h ago, last 10 h ago, peak #5
Critical vulnerability flagged in Sipay PrestaShop payment module
Original: CVE-2026-86405 (CRITICAL, CVSS 9.8) in Sipay PrestaShop Virtual POS Module (26.8.1 – 26.9.1): Improper cryptographic sig
A critical flaw, CVE-2026-86405, has been disclosed in versions 26.8.1 through 26.9.1 of the Sipay Virtual POS module for PrestaShop. Improper cryptographic signature verification could let attackers spoof messages and tamper with payment data, earning a maximum CVSS score of 9.8. No confirmed patch is available yet, and security researchers are urging merchants to monitor the vendor for a fix.
Why now: A maximum-severity unpatched flaw in a widely used payment module poses immediate risk to e-commerce stores.
Evidence
- CVE-2026-86405 (CRITICAL, CVSS 9.8) in Sipay PrestaShop Virtual POS Module (26.8.1 – 26.9.1): Improper cryptographic signature checks allow spoofing & data tampering. Patch not confirmed — monitor vendor. https:// radar.offseq.com/threat/cve-20… · offseq@infosec.exchange · 2
API: https://socialmediatrends-api.osmike.com/v1/trends/1613619