CoreWCF: SamlSerializer skips SignatureValue verification when SAML signing token is not an X.509 certificate (CVE-2026-54774) | HOL Guard CVE