Depends on how they're exploiting it, and not using php-fpm might only prevent it from doing the privilege escalation. If you're running Magento I'd get the patches installed as soon as you can just to be safe

