And you can take the reboot as a very strong suggestion, depending on your needs and whether there are kernel exploits to worry about (Oracle's purchase of ksplice is yet another reason I hate them). Much of the time (on select systems!) I get away with just restarting the services. Reboots really do bring peace of mind though.
Well I'm not sure it has anything to do with vulnerabilities or not. They do a large feature add on minor updates between 6.x and 6.x+1 which may or may not add new modules etc.
I design stuff to be resilient to host reboots. Then again we have a lot of kit to play with.