CVE-2026-65105 shows how a single configuration choice — binding Ollama to 0.0.0.0 — created an unauthenticated local API ...