Apache CXF: XML External Entity (XXE) Injection in W3CMultiSchemaFactory and EndpointReferenceUtils (CVE-2026-49875) | HOL Guard CVE