You are correct, both java and tomcat do need updates more often than lucee at times. I found that while it's a complete pain, the best deployment option is to deploy as a jar and upgrade tomcat and the Java environment as needed. Though the drop dead simplest on Windows is to do a JRE install, set the JRE to auto-update, then install tomcat windows binary, then install Lucee. You can copy and modify the config files from the express edition.