I think that the vast majority of stuff doesn't qualify as something that should be reported to a security team first. However, from a brief glance at the article, it appears that a remote user of a web application may be able to crash PHP entirely if he can find the right place to drop the number, denying access to all programs that depend on that PHP installation. That is a very serious bug and one incident can theoretically take out hundreds or thousands of sites and cost a lot of people a lot of money, not to mention time or frustration. Definitely seems like it should have hit the security group first to me.
Perhaps the real issue is that the growing reliance upon internet services makes fault-tolerant engineering and fallback plans for handling failures very important. We need to make sure that hospitals/police/everything aren't dependent on systems that might break down completely because of bugs like this.
Yes, which is why you should carefully reduce the number of bugs in your code - many bugs can be security issues, if the attacker is clever enough.