A state organization IMO should protect the public interest. If anything the NSA should be releasing CVEs and protecting US companies by patching their systems. I don’t understand what service exactly does the NSA (and similar intelligence agencies elsewhere) provide to their public by hiding vulnerabilities from the public. Does the victim of a hack that the NSA could have crates pay taxes? What for???
More than half the NSA's actual, chartered job, and the part of NSA's job that precedes every other job to which it has been assigned, is to collect signals intelligence from foreign states. Modern SIGINT involves exploits. Publishing exploits, even after you're done using them, harms that mission. Does that appropriately answer the "what for???" question?
A reasonable complaint about NSA is that the IAD (defensive) mission doesn't belong in the same agency as SIGINT or TAO or whatever they're calling it now. But that doesn't have much to do with this story; the SIGINT mission of any major government is going to (1) collect exploits and (2) almost never publish them, because that's how SIGINT is done.
NSA collecting exploits doesn't prevent anyone else from discovering and reporting the same vulnerabilities. So maybe your complaint is that we're not funding enough defensive vulnerability research?
My point is the NSA and foreign counterparts do a disservice to their citizens. I would see the value in publishing vulnerabilities, I don’t see value for taxpayers in what they are doing now.