CVE-2016-4437
published 2016-06-07CVE-2016-4437: Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass…
PriorityP196critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
92.99%
99.8th percentile
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | aurora | >= 0.10.0 < 0.18.1 | 0.18.1 |
| apache | shiro | < 1.2.5 | 1.2.5 |
| apache | shiro | >= 0 < 1.2.5-1 | 1.2.5-1 |
| apache | shiro | >= 0 < 1.2.5-1 | 1.2.5-1 |
| apache | shiro | >= 0 < 1.2.5-1 | 1.2.5-1 |
| debian | shiro | < shiro 1.2.5-1 (bookworm) | shiro 1.2.5-1 (bookworm) |
| jeesite | jeesite | — | — |
| redhat | fuse | — | — |
| redhat | jboss_middleware_text-only_advisories | — | — |
Detection & IOCsextracted from sources · hover to see the quote
commandGET / HTTP/1.1 with Cookie: rememberMe={{base64(concat(base64_decode("QUVTL0NCQy9QS0NTNVBhZA=="),aes_cbc(..., base64_decode("kPH+bIxk5D2deZiIxcaaaA=="), ...)))}}↗
- →Detect exploitation attempts by monitoring HTTP requests containing a 'rememberMe' cookie with an unusually large or base64-encoded payload, especially when the application is Apache Shiro prior to 1.2.5. ↗
- →Alert on use of the known default AES-128-CBC key (base64: kPH+bIxk5D2deZiIxcaaaA==) in rememberMe cookie decryption — presence of this key indicates the default/unpatched configuration is being exploited. ↗
- →Use out-of-band (DNS/HTTP) interaction detection: a successful exploit triggers a DNS callback; monitor for DNS lookups originating from the target server following a rememberMe cookie submission. ↗
- →Flag Java deserialization gadget chain payloads (e.g., CommonsCollections2) delivered via the rememberMe cookie in HTTP GET requests to Apache Shiro endpoints. ↗
- →Match on HTTP GET requests where the Cookie header contains 'rememberMe=' with a base64 payload that, when decoded, begins with AES-CBC IV bytes — indicative of the Shiro deserialization attack pattern. ↗
- ·The default hardcoded AES key is only exploitable when no custom cipher key has been configured for the 'remember me' feature. If a custom key is set but known/leaked, the vulnerability may still be exploitable. ↗
- ·The vulnerability affects Apache Shiro before 1.2.5; versions using a static/default cipher key for 'Remember Me' are at risk regardless of other configuration. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vulncheck9.8CRITICAL
cisa9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Apache Shiro vulnerability
vendor_ubuntu·2024-12-05
CVE-2016-4437 Apache Shiro vulnerability
Title: Apache Shiro vulnerability
Summary: Apache Shiro could be made to run programs or expose sensitive information
over the network.
It was discovered that Apache Shiro used a static cipher within the
"Remember Me" feature inside authentication by default. An attacker could
possibly use this issue to achieve remote code execution or obtain
sensitive information.
Instructions: In general, a standard system update will make all the necessary changes.
CISA
Apache Shiro Code Execution Vulnerability
cisa·2021-11-03·CVSS 9.8
CVE-2016-4437 [CRITICAL] CWE-284 Apache Shiro Code Execution Vulnerability
Vulnerability: Apache Shiro Code Execution Vulnerability
Affected: Apache Shiro
Apache Shiro contains a vulnerability which may allow remote attackers to execute code or bypass intended access restrictions via an unspecified request parameter when a cipher key has not been configured for the "remember me" feature.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2016-4437
Remediation Due Date: 2022-05-03
Red Hat
shiro: Security constraint bypass
vendor_redhat·2016-06-03·CVSS 9.8
CVE-2016-4437 [CRITICAL] CWE-287 shiro: Security constraint bypass
shiro: Security constraint bypass
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter.
It was found that Apache Shiro uses a default cipher key for its "remember me" feature. An attacker could use this to devise a malicious request parameter and gain access to unauthorized content.
Package: shiro-core (Red Hat JBoss A-MQ 6) - Affected
Package: shiro-core (Red Hat JBoss Fuse 6) - Affected
Package: shiro-core (Red Hat JBoss Fuse Service Works 6) - Affected
Package: shiro-core (Red Hat OpenShift Enterprise 2) - Affected
Debian
CVE-2016-4437: shiro - Apache Shiro before 1.2.5, when a cipher key has not been configured for the "re...
vendor_debian·2016·CVSS 9.8
CVE-2016-4437 [CRITICAL] CVE-2016-4437: shiro - Apache Shiro before 1.2.5, when a cipher key has not been configured for the "re...
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter.
Scope: local
bookworm: resolved (fixed in 1.2.5-1)
bullseye: resolved (fixed in 1.2.5-1)
sid: resolved (fixed in 1.2.5-1)
trixie: resolved (fixed in 1.2.5-1)
VulDB
Apache Shiro up to 1.2.4 Cipher Key access control (ID 137310 / EDB-48410)
vuldb·2026-04-23·CVSS 9.8
CVE-2016-4437 [CRITICAL] Apache Shiro up to 1.2.4 Cipher Key access control (ID 137310 / EDB-48410)
A vulnerability, which was classified as critical, has been found in Apache Shiro up to 1.2.4. This impacts an unknown function of the component Cipher Key Handler. The manipulation leads to improper access controls.
This vulnerability is uniquely identified as CVE-2016-4437. The attack is possible to be carried out remotely. Moreover, an exploit is present.
It is advisable to upgrade the affected component.
OSV
Improper Access Control in Apache Shiro
osv·2022-05-14
CVE-2016-4437 [CRITICAL] Improper Access Control in Apache Shiro
Improper Access Control in Apache Shiro
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter.
GHSA
Improper Access Control in Apache Shiro
ghsa·2022-05-14
CVE-2016-4437 [CRITICAL] CWE-284 Improper Access Control in Apache Shiro
Improper Access Control in Apache Shiro
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter.
GHSA
GHSA-v28f-cf4w-7rcj: Jeesite 1
ghsa_unreviewed·2022-04-06·CVSS 9.8
CVE-2020-19229 [CRITICAL] CWE-502 GHSA-v28f-cf4w-7rcj: Jeesite 1
Jeesite 1.2.7 uses the apache shiro version 1.2.3 affected by CVE-2016-4437. Because of this version of the java deserialization vulnerability, an attacker could exploit the vulnerability to execute arbitrary commands via the rememberMe parameter.
OSV
CVE-2016-4437: Apache Shiro before 1
osv·2016-06-07·CVSS 9.8
CVE-2016-4437 [CRITICAL] CVE-2016-4437: Apache Shiro before 1
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter.
VulnCheck
Apache Shiro Code Execution Vulnerability
vulncheck·2016·CVSS 9.8
CVE-2016-4437 [CRITICAL] CWE-284 Apache Shiro Code Execution Vulnerability
Apache Shiro Code Execution Vulnerability
Apache Shiro contains a vulnerability which may allow remote attackers to execute code or bypass intended access restrictions via an unspecified request parameter when a cipher key has not been configured for the "remember me" feature.
Affected: Apache Shiro
Required Action: Apply updates per vendor instructions.
Exploitation References: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
Exploit PoC: https://vulncheck.com/xdb/67abb858193d; https://vulncheck.com/xdb/6535af761e5c; https://vulncheck.com/xdb/d7a43fa66a9e; https://vulncheck.com/xdb/c53d22555992
Remediation Due: 2022-05-03
Suricata
ET EXPLOIT Possible Apache Shiro 1.2.4 Cookie RememberME Deserial RCE (CVE-2016-4437)
suricata·2021-10-27·CVSS 9.8
CVE-2016-4437 [CRITICAL] ET EXPLOIT Possible Apache Shiro 1.2.4 Cookie RememberME Deserial RCE (CVE-2016-4437)
ET EXPLOIT Possible Apache Shiro 1.2.4 Cookie RememberME Deserial RCE (CVE-2016-4437)
Rule: alert http any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT Possible Apache Shiro 1.2.4 Cookie RememberME Deserial RCE (CVE-2016-4437)"; flow:established,to_server; http.cookie; bsize:>125; content:"rememberMe="; startswith; fast_pattern; reference:url,issues.apache.org/jira/browse/SHIRO-550; reference:cve,2016-4437; classtype:attempted-admin; sid:2034256; rev:2; metadata:attack_target Server, created_at 2021_10_27, cve CVE_2016_4437, deployment Perimeter, deployment Internal, confidence Medium, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2024_03_26, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_F
Suricata
ET EXPLOIT Amcrest Camera and NVR Buffer Overflow Attempt (CVE-2020-5735)
suricata·2021-10-27·CVSS 8.8
CVE-2016-4437 [HIGH] ET EXPLOIT Amcrest Camera and NVR Buffer Overflow Attempt (CVE-2020-5735)
ET EXPLOIT Amcrest Camera and NVR Buffer Overflow Attempt (CVE-2020-5735)
Rule: alert tcp any any -> [$HOME_NET,$HTTP_SERVERS] 37777 (msg:"ET EXPLOIT Amcrest Camera and NVR Buffer Overflow Attempt (CVE-2020-5735)"; flow:established,to_server; http.cookie; content:"|62 00 00 00|"; startswith; content:"Protocol|3a 20|"; distance:0; fast_pattern; content:"|0d 0a|"; distance:200; reference:url,www.exploit-db.com/exploits/48304; reference:cve,2016-4437; reference:cve,2020-5735; classtype:attempted-admin; sid:2034257; rev:2; metadata:attack_target Server, created_at 2021_10_27, cve CVE_2020_5735, deployment Perimeter, deployment Internal, confidence High, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2021_10_27, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_t
Exploit-DB
Apache Shiro 1.2.4 - Cookie RememberME Deserial RCE (Metasploit)
exploitdb·2020-05-01
CVE-2016-4437 Apache Shiro 1.2.4 - Cookie RememberME Deserial RCE (Metasploit)
Apache Shiro 1.2.4 - Cookie RememberME Deserial RCE (Metasploit)
---
##
# This module requires Metasploit: https://metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##
class MetasploitModule 'Apache Shiro v1.2.4 Cookie RememberME Deserial RCE',
'Description' => %q{
This vulnerability allows remote attackers to execute arbitrary code on vulnerable
installations of Apache Shiro v1.2.4.
},
'License' => MSF_LICENSE,
'Author' =>
[
'L / l-codes[at]qq.com' # Metasploit module
],
'References' =>
[
['CVE', '2016-4437'],
['URL', 'https://github.com/Medicean/VulApps/tree/master/s/shiro/1']
],
'Platform' => %w{ win unix },
'Arch' => [ ARCH_CMD ],
'Targets' =>
[
[
'Unix Command payload',
'Arch' => ARCH_CMD,
'Platform' => 'unix',
'DefaultOptions' => {'PAYLOAD' =
Metasploit
Apache Shiro v1.2.4 Cookie RememberME Deserial RCE
metasploit
Apache Shiro v1.2.4 Cookie RememberME Deserial RCE
Apache Shiro v1.2.4 Cookie RememberME Deserial RCE
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apache Shiro v1.2.4. Note that other versions of Apache Shiro may also be exploitable if the encryption key used by Shiro to encrypt rememberMe cookies is known.
Nuclei
Apache Shiro 1.2.4 Cookie RememberME - Deserial Remote Code Execution Vulnerability
nuclei·CVSS 9.8
CVE-2016-4437 [CRITICAL] Apache Shiro 1.2.4 Cookie RememberME - Deserial Remote Code Execution Vulnerability
Apache Shiro 1.2.4 Cookie RememberME - Deserial Remote Code Execution Vulnerability
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter.
Template:
id: CVE-2016-4437
info:
name: Apache Shiro 1.2.4 Cookie RememberME - Deserial Remote Code Execution Vulnerability
author: iamnoooob,rootxharsh,pdresearch
severity: high
description: |
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter.
impact: |
Remote code execution
remediation: |
Upgrade to a patc
Bugzilla
CVE-2016-4437 shiro: Security constraint bypass
bugzilla·2016-06-07·CVSS 9.8
CVE-2016-4437 [CRITICAL] CVE-2016-4437 shiro: Security constraint bypass
CVE-2016-4437 shiro: Security constraint bypass
A default cipher key is used for the "remember me" feature when not
explicitly configured. A request that included a specially crafted request
parameter could be used to execute arbitrary code or access content that
would otherwise be protected by a security constraint.
References:
http://seclists.org/oss-sec/2016/q2/466
Discussion:
This issue has been addressed in the following products:
Red Hat JBoss A-MQ 6.3
Via RHSA-2016:2036 https://rhn.redhat.com/errata/RHSA-2016-2036.html
---
This issue has been addressed in the following products:
Red Hat JBoss Fuse 6.3
Via RHSA-2016:2035 https://rhn.redhat.com/errata/RHSA-2016-2035.html
Recorded Future
June 2026 CVE Landscape
blogs_recorded_future·2026-07-10·CVSS 9.1
CVE-2026-35616 [CRITICAL] June 2026 CVE Landscape
## June 2026 CVE Landscape
In June 2026, Insikt Group® identified 60 high-impact vulnerabilities that should be prioritized for remediation , 30 of which had a Very Critical Recorded Future Risk Score. This represents a 49% increase from last month. 23 of the 60 vulnerabilities were included in the US Cybersecurity and Infrastructure Security Agency (CISA)’s Known Exploited Vulnerabilities (KEV) catalog, 34 were reported by vendors, and three were primarily surfaced through honeypot data.
The 60 vulnerabilities in this report affected products from 36 vendors, with Microsoft accounting for approximately 18% of the vulnerabilities. The remaining exposure was concentrated across a range of enterprise software, security products, network infrastructure, developer tooling, and cloud platform
Hackernews
New SharkLoader Malware Deploys Cobalt Strike in StrikeShark Cyberattacks
blogs_hackernews·2026-06-26·CVSS 9.8
CVE-2021-26855 [CRITICAL] New SharkLoader Malware Deploys Cobalt Strike in StrikeShark Cyberattacks
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## New SharkLoader Malware Deploys Cobalt Strike in StrikeShark Cyberattacks
A newly discovered cyber attack campaign has been observed delivering a previously undocumented malware family called SharkLoader that acts as a loader for deploying Cobalt Strike Beacon on compromised hosts.
Kaspersky, which is tracking the activity under the moniker StrikeShark , said the campaign has targeted a diplomatic organization in Indonesia, government organizations in Taiwan, software development companies across multiple countries, and entities associated with other sectors located in Hong Kong, Lebanon, Syria, Colombia, North Macedonia, Ne
Securelist
StrikeShark: investigating a new campaign delivering Cobalt Strike through SharkLoader
blogs_securelist·2026-06-24
CVE-2021-26855 StrikeShark: investigating a new campaign delivering Cobalt Strike through SharkLoader
Fareed Radzi
Table of Contents
Introduction
Initial infection
Exploitation of public-facing applications
Dropper-based distribution
SharkLoader installation
SharkLoader DLL – Main implant
“PerfectDLL Hijacking” technique
Decryption and loading of >DscCoreR.mui
DscCoreR.mui and SyncRes.dat DLLs
Decryption and loading of SyncRes.dat
SyncRes.dat decrypted DLL: Multiple API hooks
VEH registration and access violation handling
Thread creation for Cobalt Strike Beacon execution
MinHook DLL, API hooking, and Cobalt Strike beacon
Persistence mechanism
Post-compromise activity
Victimology
Attribution
Conclusion
Indicators of compromise
Authors
Fareed Radzi
## Introduction
During our research of activity affecting a diplomatic organization in Indonesia, we uncovered a previo
Greynoiseio
NoiseLetter February 2026
blogs_greynoiseio
NoiseLetter February 2026
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
http://packetstormsecurity.com/files/137310/Apache-Shiro-1.2.4-Information-Disclosure.htmlhttp://packetstormsecurity.com/files/157497/Apache-Shiro-1.2.4-Remote-Code-Execution.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2035.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2036.htmlhttp://www.securityfocus.com/archive/1/538570/100/0/threadedhttp://www.securityfocus.com/bid/91024https://lists.apache.org/thread.html/ef3a800c7d727a00e04b78e2f06c5cd8960f09ca28c9b69d94c3c4c4%40%3Cannouncements.aurora.apache.org%3Ehttp://packetstormsecurity.com/files/137310/Apache-Shiro-1.2.4-Information-Disclosure.htmlhttp://packetstormsecurity.com/files/157497/Apache-Shiro-1.2.4-Remote-Code-Execution.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2035.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2036.htmlhttp://www.securityfocus.com/archive/1/538570/100/0/threadedhttp://www.securityfocus.com/bid/91024https://lists.apache.org/thread.html/ef3a800c7d727a00e04b78e2f06c5cd8960f09ca28c9b69d94c3c4c4%40%3Cannouncements.aurora.apache.org%3Ehttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-4437
2016-06-07
Published
2021-11-03
Added to CISA KEV
Exploited in the wild