That issue mentioned in the firmware release only affected the MX84's (which have now had EOS announced). It was mostly around changing changes to the interfaces (such as changing VLANS, VLAN trunking, etc).
I haven't worked on any MX250's, but none of the other products (including the MX84) looses any packets during a firewall rule change. I do firewall rule changes a lot.
You can't argue with a packet capture. Perhaps the issue is specific to the MX250, or perhaps it is related to the firmware version being used on the MX250. Are you able to upgrade the firmware on just one of the MX250's and do some further experiments?
ps. I've found AnyConnect on MX to be very solid.