Cacti: Command Injection via escape_command() no-op in RRDtool execution (CVE-2026-40079) | HOL Guard CVE