There are known vulnerabilities in that version of jQuery but we are confident that there is little scope for those to be exploited in the context of how the relevant functions are used in XF 2.1 hence why we waited until XF 2.2 before upgrading jQuery which was preferable due to some backwards compatibility issues.
We will update the XF.com home page in due course to the 2.2 code base.