Patch both trains. The four high-severity fixes are the ones to read first: a denial of service in the App Router via Server Actions, a middleware and proxy bypass that hits apps running Turbopack with a single locale, and two separate server-side request forgeries — one through rewrites with an attacker-controlled destination hostname, the other in Server Actions on custom servers. That last one is the sharp edge if you self-host rather than deploy on Vercel's managed edge. The five moderate advisories cover two cache-confusion bugs, a DoS in the Image Optimization API triggered by SVGs, unauthenticated disclosure of internal Server Function endpoints, and an unbounded Server Action payload on the Edge runtime. Nothing here is a breaking change, so the upgrade is a version bump, not a migration. If you're on 16.2.x or 15.5.x, take it today.