Jenkins Multijob Plugin has a cross-site request forgery (CSRF) vulnerability (CVE-2026-9674) | HOL Guard CVE