Condense the supplied security advisory for affected users who need to assess exposure and act. This is an editing task, not a new vulnerability assessment or an instruction to test an exploit. Lead with the affected product, versions, and required exposure conditions. State the documented impact. Preserve authentication requirements, configuration limits, fixed versions, mitigations, and whether a workaround reduces or removes the stated exposure. Keep advisory identifiers and links supplied for verification. Separate confirmed exploitation, no known exploitation, and exploitation status unknown. Preserve uncertainty and the date of time-sensitive claims. Remove repeated severity adjectives, background that does not affect action, and unnecessary exploit detail. Do not invent a severity score, assign an identifier, or expand affected versions by inference. Output Exposure, Action, and Evidence lines as supported. Retain operational costs of a mitigation. Do not state that a system is safe merely because it uses a workaround, or claim that an update has been applied.