That’s basically my experience as well. Just upgrading is much easier and cheaper.
Of course with latest supply chain failures we don’t update right away or automatically.
If it is RCE in a component that is exposed then of course we do it ASAP. But those are super rare.