Unlike nuclear weapons, there aren't a lot of rare resources required for discovering vulnerabilities, so the approaches that help with nuclear nonproliferation will not help with digital security. All one needs is to find vulnerabilities is smart people (and maybe a lot of computing resources to brute force fuzz a lot of software). There are a lot of smart people and fast computers out there, and the ones not in the US almost certainly outnumber those that are inside the US. It seems it would be much better to defend against them and disarm entirely rather than hope to stay ahead of them.
On some authority, you're asking me to put myself in the position of an NSA leader. I'm not an NSA leader. Postponing the bug fixes hurts me, and the rest of the people like me. Fix them.
Its possible that the right answer is we should have a US agency finding bugs and getting them patched, but it certainly shouldn't be any of the intelligence agencies. That feels a little too like putting the military in charge of the police force.