
Sipay PrestaShop & OpenCart Sanal POS’ta CVSS 9.8 kritik açık:• CVE-2026-86405 (PrestaShop) • CVE-2026-85531 (OpenCart)Kriptografik imza hatası nedeniyle sahte ödeme onayı ile ödeme kontrolü baypas edilebiliyor.Acilen 26.9.1+ sürüme güncelleyin.
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
Improper verification of cryptographic signature vulnerability in Sipay Electronic Money and Payment Services Inc. OpenCart Virtual POS Module allows Signature Spoofing by Improper Validation. This issue affects OpenCart Virtual POS Module: from 26.8.2 before 26.9.1.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
STABLE

Sipay PrestaShop & OpenCart Sanal POS’ta CVSS 9.8 kritik açık:• CVE-2026-86405 (PrestaShop) • CVE-2026-85531 (OpenCart)Kriptografik imza hatası nedeniyle sahte ödeme onayı ile ödeme kontrolü baypas edilebiliyor.Acilen 26.9.1+ sürüme güncelleyin.

🚨 CVSS 9.8 — Sipay Virtual POS signature spoofing hits OpenCart & PrestaShop CVE-2026-85531 + CVE-2026-86405: 🔗 https://threataft.com/articles/sipay-virtual-pos-signature-spoofing-cve-2026-85531-86405 #CVE #PaymentSecurity #OpenCart #PrestaShop #CyberSecurity

Sanal POS kullanan e-ticaret işletmelerine önemli güvenlik uyarısı! 🔐 Sipay OpenCart Sanal POS Modülünde Güvenlik Açığı Tespit Edildi! T.C. Cumhurbaşkanlığı Siber Güvenlik Başkanlığı, Sipay tarafından geliştirilen OpenCart Sanal POS Modülü’nde CVE-2026-85531 kodlu güvenlik açığı tespit edildiğini duyurdu. https://www.fintekwins.com/sipay-opencart-sanal-pos-modulunde-guvenlik-acigi-tespit-edildi/