Java remains a prime target for supply chain attacks. Many addons rely on old logging libraries. A often closes a remote code execution (RCE) hole. If you see "v10 patched" in a changelog, it likely means the developers have: