This Slashdot article says it all:
http://it.slashdot.org/article.pl?sid=08/12/10/206216
Unfortunately, it doesn't look as if there are any fixes in the works. One of the exploits involves the XML parser used by MSIE and another is an exploit in the "WordPad Text Converter" (honestly, HOW?). I'll post updates as fixes become available. For now, browse safely.
Edit: Changing to sticky for now.