TS3 Manager: Reflected XSS via /api/download port parameter steals operator session (CVE-2026-54253) | HOL Guard CVE