This is a security release.
The decision to include support for svg files by default in JCE 2.6.25 was unfortunately not well thought through. It has been brought to my attention that there is the potential for svg files to be used to execute cross-site scripting attacks, due to the fact that they are essentially a form of xml file. Although the method by which they would be embedded using the Image Manager, with the <img> tag, prevents scripts from being executed, it would be safer to restrict the option of allowing svg files to be user defined.
Download and Installation
Instructions for installing and updating JCE for each Joomla version are available here