Just because no one managed to create WannaCry for Flash doesn't mean the security problems are overstated. They've published over 50 vulnerabilities in Flash this year, when the installed base is in the toilet.
Java may be worse (or it may not be, but I would avoid installing either on most client machines), but blowing a bigger hole in the system's defenses doesn't really make the slightly smaller hole any less of a problem, it just changes your priorities in patching.
The only thing impressive about Adobe's security record is the number of times their source code was compromised.