I'm interpreting the likelihood of encountering this near term seems very low, and the impact is high enough where an APT group uses it as part of their pivot and persistence strategy, but it's mitigated by the fact that it doesn't compromise a clients private key. There may be some future implementation of this attack that enables automated ssh session hijacking as a result of a key downgrade and an additional cryptographic weakness in that chosen weaker cipher. It implies the network IoCs would be for a bunch of NOP ssh packets and failed ssh session setups.
Interested in disagreement.