When you use the latest-minor as your requiredMinimumOSVersion, the Actively Exploited CVE check still considers macOS versions higher than the current major version for CVE purposes resulting in a false indication.
For example if your computer has macOS 15.7.3 the reported update will correctly be 15.7.4, but the Active Exploited CVE will indicate there are updates present that are not actually contained in 15.7.4.