With Hyperflex in the later stages of support you should get used to applying patches direct from VMware.
https://www.cisco.com/c/en/us/td/docs/hyperconverged_systems/HyperFlex_HX_DataPlatformSoftware/HyperFlex_upgrade_guide/5-5/b-hx-upgrade-guide-for-vmware-esxi-5-5/m-upgrade-vsphere.html#Cisco_Task_in_List_GUI.dita_7f579103-fe92-4ff2-84b9-37aacbe9515d
Cisco does not recommend use of non-HX customized ESXi bundles, although it is supported.
There are only two more Hyperflex releases planned (not guaranteed).
Typically Hyperflex only updates HX ESXi builds with new Hyperflex releases.
You can either wait (a month or two or longer) or proceed with patches from VMware.
If it were my environment given the criticality of these CVEs. . . I would have already applied the patches from VMware.