Considering switching away from Fedora and to another distribution. Does anyone have any suggestions for distributions I should consider?
Yes, this is correct. The way Testing works, it is very possible (indeed, likely) that you could be stuck with a security vulnerability for weeks. You should use either stable or unstable.
Yes, as long as you pay attention to what packages are being added and removed when you perform an update. Once in a great while, there have been instances of buggy packages mass-removing other packages due to a bug.
That said, Debian-based distros like Ubuntu usually base their stable releases on unstable. Unstable doesn’t refer to software stability. Rather, it refers to the idea that the system-level packages could change throughout the development cycle.
Security updates come to unstable through normal package updates, which testing doesn’t get until everything makes it through a probationary period with no “serious” bugs filed and no dependency issues. And if any package that the package needing the security patch depends on also has a serious bug filed, the process could take even longer.