Cacti: Open Redirect via HTTP_REFERER substring check in auth_login_redirect (CVE-2026-40080) | HOL Guard CVE