Is it good idea to run "yum update -y" automatically on production node as a cronjob for example? Can you explain why?

How to modiffy yum update so it will isntall only critical bug fixes, exploits automatically?