The patch pointed to a KB which wasn't available, so I was wary of it and didn't install it on any of our management boxes--which patch automatically. I patch all our servers manually.
1. Yes. It was unacceptable that this was released, but sometimes planes crash and bridges fail. They'll fix it.
2. KB should be live and say: "This is in testing. Do not install in a production environment". Pull the trigger on the KB at the same time you do the update.
3. I run clean, pristine, simple boxes with grown-up *current* hardware and software: Dell 2950/MD1000, the surprisingly superb Trend ScanMail (and therefore unfortunately: Java), Symantec SEP, BESR, RAWS. And that's it. I do this so that I can rely on the multibillion dollar corporation to adequately test against a standard configuration, because it's going to do it better than I am.