If you are using a base image and not a custom image Automatic Guest Patching might be an option for you.
However, if you are using a custom image, you will need to use either Automatic OS Image Upgrades (only available if using Uniform Orchestration mode) or update the VMSS Image.
Alternatively, you could update the individual VMs, however this would not automatically update new VMs. Perhaps a workaround would be to update the VMSS custom data.
You can setup the appropriate Upgrade Policy so that updates to the OSImage will not have impact on your workload.
Hope this helps. Let me know if you have specific questions or run into any issues.
If you still have questions, please let us know in the "comments" and we would be happy to help you. Comment is the fastest way of notifying the experts.
If the answer has been helpful, we appreciate hearing from you and would love to help others who may have the same question. Accepting answers helps increase visibility of this question for other members of the Microsoft Q&A community.
Thank you for helping to improve Microsoft Q&A!