If I'm reading this right, this is something that sounds a little bit like Apache MultiViews but isn't.
1. It doesn't sound like they were using MultiViews at all but some rewrite rule that rerouted all requests ending in .srv to a shell script in /bin. This isn't how MultiViews works. The file must exist, and it must be in the document root. A request to /foo won't work unless /foo.php (or foo.html, etc.) exists.
2. This rerouting was supposed to happen only for admins, but the authorization failed, due to a different bug, CVE-2018-10661.
3. The attack then depended on a bug in dbus, CVE-2018-10662
4. Finally it depended on a third flaw, CVE-2018-10660, having to do with shell-script injection.
So I don't think any of this should scare away a person from using MultiViews for .php scripts, which makes setting up clean, maintainable routes easier than any other technique I've seen.