That doesn't seem correct:
If they determine the vulnerability is only exploitable by the NSA for reasons
such as computational resources, budget, or skill set, they label it as NOBUS
and will not move to patch it, but rather leave it open to exploit against current
or future targets.
If (!) the NSA regards ssh keys as secure, then from that article it sounds like the NOBUS thing would fit.