Bottom line use what you feel comfortable with.
We've used Sendmail on all of our servers from day one, and haven't had one problem.
Do you need to do patches? Sure security patches are an unfortunate part of administrering a network.
Should you look at using something different becuse of it?
Hell no, not if you don't want to. If you were going to take that path.. then you'd need to find replacements for:
OpenSSL, ModSSL, Bind, Apache, Linux Kernel, Mozilla, QT, Gaim, libpng, Samba, PHP, syslogd, cvs, XFree86, procmail, pine, OpenOffice, GTK+, Gnome, sudo, KDE (need I go on?)
Hell QMail has had it's share of security problems as well
The fact there is a need for a patch shouln't concern you.. the timely maner in which a patch was produced should be.
I recommend you signup for security notifications from your Linux Dist., as well as from any third party apps (modssl etc) you install seperatly from the dist vendor.
Regards
KC