Security, AI, and other curiosities
FortiSandbox CVE-2026-39808 unauthenticated root RCE PoC drops with single-curl exploit; Thymeleaf CVE-2026-40478 SSTI sandbox bypass enables RCE on Spring/Java apps via whitespace parsing gap.