If you don't update you are exposed for these bugs, some only apply in specific unlikely scenarios - some can be on more likely ones (for example I well remember SP firmware bug the crashes ONTAP OS after 500 days of SP uptime).
As for single-path IO. TBH I can't find a special procedure for such updates, but I assume it cannot be done on an IOM that a controller is using. I'm tempted to tag @andris - any idea how the magic of updating single-path HA IOM module happens?
If you are in a single-path HA configuration, that means that each node only has one path to the shelf - i.e. it can only reach one of the IOM modules on the shelf. In that situation, your applications need to be able to handle a ~45s pause in storage I/O for the IOM module to restart after an update.
Also, make sure you download shelf and disk firmware to both nodes in an HA pair. The node that actually performs the shelf and/or disk firmware will depend on disk ownership and who the "storage master node" is...