This is because I discovered that Let's Encrypt was issuing non-compliant certificates: <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1838667" rel="nofollow noreferrer">https://bugzilla.mozilla.org/show_bug.cgi?id=1838667</a>
On the bright side, that's actually one of the lower-impact things to have an outage on, IMO; if you're using it the recommended way, an outage would only really affect new certs, with older certs just getting renewed slightly later.
What's the impact of an outage like this? ACME renewals should happen daily starting 30 days before expiry so no one should have had a cert expire due to this. New certificates wouldn't have been issued, so that's impact, although I suspect most new certs aren't taking traffic immediately (i.e. setting up a new server).