SD-70610 : XSS vulnerability in add new request form’s 'insert image' section is fixed.
SD-71186 : If PM tasks are created using templates with service catalog additional fields, then the back up (with 9404 data in particular) and restore operations on a fresh installation fails.
Please refer to the below link for the steps to install the patch.