The updated packages fix security vulnerabilities: Heap Out-of-Bounds Read in HandleUltraZipBPP due to unchecked subrectangle count. (CVE-2026-32853) NULL pointer dereferences in httpd proxy handlers via malformed CONNECT/GET requests. (CVE-2026-32854) LibVNCClient Tight Gradient decoding allows malicious server-triggered heap/stack OOB writes. (CVE-2026-44988) Attacker-controlled heap out-of-bounds write in libvncclient Tight decoder. (CVE-2026-50538)