A recent update (Keycloak 26.7.2) released on August 19, 2026, addresses five vulnerabilities, notably the critical CVE-2026-18963, which allows unauthenticated account takeover through a password reset bypass. This flaw has a CVSS score of 9.1, indicating its high severity. Other significant vulnerabilities include CVE-2026-15571, which can be exploited by a malicious OIDC client to take over accounts. Users are urged to apply the latest security updates immediately, as no public exploitation has been confirmed yet.
Keycloak fixes critical CVE-2026-18963 password reset bypass flaw
CyberSIXT Evidence Panel
Article by CyberSIXT