Combodo iTop: Remote code execution using external auth variable value (CVE-2026-39975) | HOL Guard CVE