I don't care whether a given processor is microcoded via a tiny ROM, or whether it is all hard-wired gates; the difference is just in the instruction execution timings.
We are not "hosed" in any way by this.
As soon as the microcode is writable, then we have questions: can anyone write any arbitrary microcode and put it in place? Or is there some tamper-proof layer containing that only accepts signed microcode, and who has the keys?