What is a good patch/update management server?
Shavlik's NetChk Protect could be a good option for you. The company has a close relationship with Microsoft and its underlying technology powers Microsofts own Baseline Security Analyzer product. Whilst Microsoft's MBSA only supports patching Microsoft products NetChk Protect support products from many other vendors.
There are quite a few products out there which support this LanDesk, Altiris and PatchLink to name a few.
To the best of my knowledge all the products out there are walled gardens.