CVE-2026-34486: one moved line turned Tomcat's cluster encryption into RCE
The fix for a padding-oracle bug in Apache Tomcat's cluster encryption moved super.messageReceived() outside its try block. On the affected versions, a decrypt failure now forwards attacker bytes to a bare