

I think the biggest one in recent (past year) would have been the upgrade tree to nvidia-open, which would break 10-series and older support without changing package on affected systems. Definitely a lot of the more recent breakages are not large-scale problems, but they do still exist.
Generally, your auth provider (assuming setup correctly) should be one of the most secure components of your internet-exposed setup. That being said, vulnerabilities can and do occur. Adding a combination of Crowdsec, OWASP CRS, other ModSecurity rulesets, and/or fail2ban will add a degree of migitation of potential exploits by blacklisting known bad actors/active bad behavior.
Above all, you should have a plan to keep aware of updates to your publicly-exposed software and be able to deploy those updates in a timely fashion.