Thanks, according to David these vulnerabilities aren’t massively exploitable across the board – so I haven’t triggered an alert for the roughly 30 updated extensions just yet. I’ll see how to handle this going forward.
Especially since compatibility sometimes breaks (Free vs. Pro differences), auto-updates triggered here would probably be a bad idea.