Both vendors admit attackers were already exploiting the bugs, with scant detail and quiet hints of spyware-grade abuse.