Until recently, Flash didn't even use any hardware acceleration for video. I don't believe that it actually gives the direct access to the hardware that WebGL does. So while it's still a security risk(especially given Adobe's track record), I'm not entirely convinced that it's a greater potential risk than WebGL.
True. Flash is a plugin that Adobe ships, whereas IE is the responsibility of Microsoft because it ships with Windows. Flash taking a risky bet is different from the IE shipping potentially vulnerable code with the Windows box.