If decryption fails, the message goes through anyway
The fix for the Apache Tomcat vulnerability CISA flagged as exploited on 4 August fits in a single line of code moved somewhere else. For two weeks, if decryption of a cluster message failed, Tomcat logged the error and processed the message anyway. And only 11.0.20, 10.1.53 and 9.0.116 were affected: precisely the versions carrying the patch for the previous flaw. What it means for a control to "fail open", why the log was the only signal, and what we check.