The last I checked, Shell_exec() was not supposed to be enabled in the first place as it's been disabled for MONTHS before this massive server move took place. Right now cPanel is a bit messed up on my server and the server's CPU load is in the 44 range, so I can't check to see if Shell is disabled yet on my server, but yet my forum has features enabled right now which use shell_exec() and they are working just fine still, so shell has to be working.
The reason it's a security issue is because it can be brute forced and executed in such a way to damage the server. Shell access is one thing that should only be accessed by very few people.