Persistent widespread exploitation of CVE-2026-3055 targeting SAML IdP endpoints. Added to CISA KEV catalog. Attackers use malformed SAML requests to leak session tokens and credentials.