Thanks for all the replies... I did suggest not to distribute any Software Update to the CMG. Hopefully we take care of that this morning. I did not think that was setup correctly.
I did notice that when I deleted the contents of the C:\windows\system32\grouppolicy folder, and the e download and SLS sub folders of c:\windows\softwaredistribution, followed by deleting the reg key for Group Policy (HKLM\software\policies\microsoft), and then rebooting - it worked fine.
I will be updating the content on the CMG's this morning and setting up the missing SSL settings for WSUS. I always struggled with the GPO's needed for WSUS when SCCM is in play. They want to be able to have that check for updates run when the VPN client (F5) starts up which is how the issue was discovered. I am leaning on a GPO causing the issue, but wonder what I need to set to have SCCM in line with these updates and for this Check for Updates to just always work.