The way SME is set up, some issues just don't affect it as they would on a default RH install. Running different processes as different users, default firewall rules, that sort of thing. It's not necessarily that the bug isn't in the SME code, it's that it can't be exploited due to the rest of the SME package.
And sometimes all it takes is the RH RPM to fix the problem (since SME is based on RH). Would you rather wait until Mitel copies the file to an Updates directory on their own server and says "Run 'rpm -Uvh xxxxx.rpm' to fix this problem."?
I'm no expert, but we haven't experienced any security problems yet...
As for the Blades, it's their service, it's their decision. If you want to be able to update your server via a Server Manager panel instead of downloading and installing RPMs, pay for it.