Even if we generate a new key pair and replace our certificate, aren’t we still vulnerable to MIM attacks if someone had downloaded the old private key and use the old certificate?
That's why it's so vital for everyone to implement Perfect Forward Secrecy. Yes, it's a little late for that now in regards to this bug, but who knows what others bugs like this will be discovered in the future. Let's at least not make the same mistake twice, by not taking advantage of PFS, which could've prevented most of the damage from Heartbleed.