CVE-2026-35390: Content-Security-Policy was set to Report-Only mode, failing to block XSS attacks — Zero Day Monitor