Microsoft changed the signing of update packages for Windows 7 and Windows Server 2008 R2 devices on the August 2019 Patch Day for the first time. The company signs packages only with SHA-2 since August 2019; it signed them with SHA-1 and SHA-2 previously but decided to drop SHA-1 because of known weaknesses.
To sort out this issue, install the following patches in order (ideally reboot after installing each) and then patch your servers successfully:
https://support.microsoft.com/en-us/help/4474419/sha-2-code-signing-support-update