This sounds like multiple RCE issues in common PGP and S/MIME software, but the details are vague so far. Or it could be a side channel issue. Hmm.https://twitter.com/EFF/status/995906839958061056 …
RCE != broken encryption. RCE == malicious email taking over your computer. That is the only reasonable explanation for why they're going with this advice. Disable broken software, disclose, update, enable again. Otherwise, you're vulnerable between "disclose" and "update".