Not really a surprise that traditional AV products are not terribly good at detecting exploits, but the extent to which they fail is perhaps a bit of a shock?

Antivirus (AV) products and traditional "Internet security suites" generally don't detect about 80 percent of the exploits and vulnerabilities they see, according to a study published earlier this week by security software vendor Secunia.
Possibly a bit of FUD, but I think that the idea that patching your OS and applications is just as if not more important, is a valid one.

Article:

http://www.darkreading.com/document....ng_section_296