A series of bugs, patched in September, still allow remote code execution by attackers.
Source: Threadpost