Help With Updating Hosts Running Cisco CSR1000V

I have a handful of remote hosts that use Cisco CSR1000v virtual appliances for routers. I would like to patch these hosts for the latest critical security CVE’s but can’t think of a good way to go about this outside of being on-site or having some sort of jump box solution that can act as OoB management. To my knowledge, none of these hosts is configured for ILO or iDRAC functionality because the original architect didn’t have the foresight to do it before they shipped out.

Am I pretty SoL here or is there something simple I’m overlooking?

