
CVE-2026-56091: Apache Shiro: Authentication bypass in Guice-Web integration https://www.openwall.com/lists/oss-security/2026/06/24/7 CVE-2026-56130: Apache Shiro: Remember-me cookie isn't checked for expiry on the server https://www.openwall.com/lists/oss-security/2026/06/24/8
Post summary
Two new Apache Shiro vulnerabilities have been disclosed: one enables authentication bypass in the Guice-Web integration, the other allows attackers to bypass cookie expiry checks on remember-me tokens. No PoC, exploit code, patch, or evidence of active exploitation is provided.


