#technical
3 posts

CVE-2026-39808 — FortiSandbox Unauthenticated RCE: How a Pipe Symbol Brought Down Enterprise Sandboxing
CVE-2026-39808 is a critical OS command injection vulnerability in Fortinet FortiSandbox that allows unauthenticated remote code execution as root via a single crafted HTTP request. Now listed on CISA's Known Exploited Vulnerabilities catalog, this flaw threatens enterprise security operations centers worldwide.

CVE-2026-48558: Critical SimpleHelp RMM Authentication Bypass — Unsigned OIDC Tokens Enable Full MSP Takeover
An in-depth technical analysis of CVE-2026-48558, a CVSS 10.0 authentication bypass in SimpleHelp RMM that lets unauthenticated attackers forge OIDC tokens, create Technician accounts, and gain administrative control over every managed endpoint. Actively exploited with TaskWeaver and Djinn Stealer payloads.

CVE-2026-48710 — BadHost: How a Single Starlette Flaw Put Millions of AI Agents at Risk
CVE-2026-48710 (BadHost) is a critical Host header validation flaw in Starlette that lets attackers bypass path-based authentication by injecting delimiter characters into the Host header. Discovered in vLLM during an OSTIF audit, this bug affects millions of AI agent deployments worldwide including FastAPI, LiteLLM, MCP servers, and major agent frameworks. We break down the root cause, exploit mechanics, affected systems, detection, and mitigation.