Are your hosts managed by vCenter Server?
In this case you can switch from the classic Update Manager to the Life Cycle Manager, and setup the desired state, which includes the VMware patches, Vendor AddOns (that's what e.h. HPE includes in their customized images), additional components (if required), and even firmware patches (which however requires additional systems).
If you are going to patch a host manually, use the latest vendor customized image, and then apply the latest VMware patches if required. Vendors like HPE usually support the VMware patches on their images for the given "Update" release, e.g. v7.0 Update 3.
André