New versions of both the Nagios 1.x and 2.x code branches have been released and contain a fix for a content length (buffer) overflow that could affect the CGIs under certain web servers (although probably not Apache). Nagios 2.3 and (for folks running 1.x versions) 1.4 can be downloaded here. The Changelog for both releases can be found here.
Nagios Update: XI 5.6.6
Nagios XI update 5.6.6 is now released! This update resolves a number of minor bugs and one security vulnerability fix. This version also includes improvements