Cacti: Arbitrary File Read via Path Traversal in Report `format_file` Parameter (CVE-2026-40084) | HOL Guard CVE