WordPress has released a critical update (3.0.4). It fixes a core security bug in our HTML sanitation library, called KSES. The download is available through the update page in your dashboard or from http://wordpress.org/download/ .
As always as I stated in a previous post ensure you have a backup of your files an database before you install the update. It does replace the style.css.