So what can one do about this? What amount of panic is appropriate?
I think the best advice is not to listen to anyone on HN about this shit except for cperciva
Original response:
----
Reimage everything from scratch if you're a bit paranoid, because in theory someone could have rooted every server running any internet-accessible thing (even just sshd or nginx)
Realistically, update ASAP and figure out from other sources how difficult this is to exploit and how likely it is that anyone actually did get a working RCE
And consider mitigations at various tech stack layers.