Part of me thinks you could read that sentence this week, next week, a month or 6 months from now and it will still hold true...
So: don't panic, but do take precautions as soon as possible.
Possibly because the issues are mostly mitigated in the wild and there are other, easier to exploit, holes out there too (particularly the water-bag problem: human engineering can be a great attack vector). So they are picking the lower hanging fruit instead. As soon as there is a PoC that seems to have a decent ROI for the implementation time, exploits will appear in the wild.
If somebody could already run that code, they'd choose anther attack method.
The real nightmare targets are cloud providers. Many smaller providers have not patched yet.