If you change a replica to sync to MS, does it then download the updates? If not, check firewall ruleshttps://learn.microsoft.com/en-us/windows-server/administration/windows-server-update-services/deploy/2-configure-wsus#211-configure-your-firewall-to-allow-your-first-wsus-server-to-connect-to-microsoft-domains-on-the-internet
Or perhaps put Bits into foreground mode
https://www.ajtek.ca/wsus/wsus-bits-foreground-priority-mode-vs-background-priority-mode/