According to WordPress.org a new security update is available(WordPress version 3.0.4), its a very important update that should be applied immediately. It fixes core security bug in the HTML sanitation library, called KSES. This release is a critical says Matt Mullenweg.
He also emphasis to update this release due to the holiday season is going on, should not be taken lightly. Its not a Christmas or Holiday release.
If your interested to see the change log you can take a look here and you can also review the update. The security bug is discovered by Mauro Gentile and Jon Cave (duck_) and alerted the WordPress team to these XSS vulnerabilities.
If you have no idea how to update it you can refer the link that will show you the update process in detail.
Download Link : WordPress version 3.0.4