It has the potential to corrupt customer data, but the likelihood and severity of the corruption hasn’t been established yet (it could be anything from flipping ECC-correctable bits through to total system compromise).
The flaw is exploitable over the network, and affects potentially all CPUs. The only way to avoid any risk of compromise is to disconnect your servers from the network.
Millions of people depend on your servers. Some of them will die if their data is corrupted. Some of them will die if you disconnect your servers and cut them off from accessing their data.
It will take security researchers about a month to work out the likelihood and severity of corruption, and about 3 months to deliver a fix. By the time we find out, the corruption may already have affected your servers. The eventual fix isn’t guaranteed to be reliable, nor can it fix corruption that has already happened.
The CVE may already have been mitigated by a previous microcode update for a similar previous issue. The security researchers are working on determining that too.
What will you do?