It fixes three RRAS vulnerabilities (CVE-2026-25172, CVE-2026-25173, CVE-2026-26111) that can allow remote code execution when connecting to a malicious server.
Part of the PlainSec briefing for 2026-03-15