CVE-2026-35207: deepinid plugin in dde-control-center is configured to skip TLS certificate verification when downloading avatar from remote server — Zero Day Monitor