WordPress MU 2.8.6 was just released and it is available for download immediately. This releases patches a XSS vulnerability in Press This and another issue with sanitizing upload file names which could be exploited to run a php file uploaded as file.php.jpg in some apache configurations. These are the same security fixes that were patched in WordPress 2.8.6. This release also addresses some MU specific bugs.