This likely has something to do with SSL config and communication between the target and the WSUS. Have a look at the solutions provided at these two links:
Thank you for the reply. The security team discovered a teeny-tiny ACL rule not allowing traffic between the SUS and target units. They don’t know how they missed it before when I asked them to check, but glad that those 2 units are now working! Thanks again for your help – I would have not thought to bug that group to look again… without your response!