What constraints do you have regarding network security? Do you control the network or only servers? What is company policy about DMZ and Inside zones interaction?
You could open the needed ports from the inside to the DMZ, only for the WSUS server.
Or, for only a handful, it might be easier to do manually.