
CVE-2026-56091: Apache Shiro: Authentication bypass in Guice-Web integration https://www.openwall.com/lists/oss-security/2026/06/24/7 CVE-2026-56130: Apache Shiro: Remember-me cookie isn't checked for expiry on the server https://www.openwall.com/lists/oss-security/2026/06/24/8
Post summary
The snippet announces two new Apache Shiro vulnerabilities: an authentication bypass in Guice-Web integration (CVE-2026-56091) and a server‑side expiry check omission for remember‑me cookies (CVE-2026-56130).


