Apache Roller: Unauthenticated deserialization in the XML-RPC endpoint (CVE-2026-82384) | HOL Guard CVE