It runs on 3.5.+ and the 3.6 beta version has been available for weeks now.
As for the exploits, the first was software based, in which I believe was fixed with the help from the vB staff. The second exploit is PHP based; nothing to do with phpPortal (vbPortal) itself. It is an issue that the developers and hosting service need to resolve.
The phpPortal developers and vB staff have been working tirelessly which is always a positive sign. Anyway, while you may already have, get the updates in the Chit Chat thread at vB.com.
Click here to the thread.