Verifying an SD-JWT VC signed with an X.509 certificate no longer verifies the credential's iss claim against the signing certificate. Previously the iss had to match a SAN-URI or SAN-DNS entry in the certificate and had to be an HTTPS URI. These legacy checks rejected otherwise-valid credentials from external issuers whose certificates do not encode the issuer URL in a Subject Alternative Name, and mainly affected SD-JWT VC verification.
The certificate chain is still validated against your trusted issuers. No action is required: presentations that previously failed on an iss mismatch now verify.