In an enterprise environment, you rely on a service that tracks CVEs, analyzes which ones apply to your environment, and prioritizes security critical updates.
The issue here is that one of these services installed a release upgrade because Microsoft mislabelled it as security update.
For security updates in critical infrastructure, no. You want that right away, in best case instant. You can't risk a zero day being used to kill people.
Besides that:
Should MS have caught the errorenous ID (assuming it truly was errourneous and not knowingly falsely labeled)? Absolutely.
Should the patch management team blindly release all updates that MS releases? No?