1) This isn't a relatively simple issue like a bug in our CA code would be. It's an interaction between the protocol and provider services.
2) Disabling TLS-SNI is a complete mitigation for us, meaning it's no longer possible to get an illegitimate certificate from Let's Encrypt by exploiting this issue.
3) We have not yet reached a conclusion as to whether or not the TLS-SNI challenge will need to remain disabled permanently.
4) At this point we have no reason to believe that the vulnerability has been exploited by anyone other than the researcher who figured it out and reported it to us.
Our focus now is on sharing information with relevant parties and looking for less drastic mitigations that might allow us to restore the TLS-SNI challenge option to people who rely on it.
We will, of course, share more information as soon as we can. That might be as soon as the next few hours, things are moving quickly.