All incidents

Multiple critical vulnerabilities patched in Keycloak and Red Hat products

vulnerabilityopenAug 20, 2026 — Aug 21, 2026
Keycloak fixes critical CVE-2026-18963 password reset bypass flaw

KEYCLOAK has issued version 26.7.2 to patch a critical authentication bypass that could let attackers seize control of user accounts without needing any credentials. The flaw, tracked as CVE-2026-18963, resides in the password reset mechanism and can be triggered by an unauthenticated remote user. Organisations that rely on Keycloak for single sign‑on now face a direct route to account takeover if the update is not applied, as detailed in the vendor’s advisory here.

The vulnerability carries a CVSS score of 9.1, reflecting its potential to compromise confidentiality, integrity and availability of the affected service. Attackers can manipulate the reset token generation process to forge a valid password reset link, thereby setting a new password for any known username. In the same release, Keycloak also addressed CVE-2026-15571, a high‑severity issue scored at 7.3 that allows a malicious OpenID Connect client to inject its own redirect URI and hijack an authentication flow. Both flaws affect all releases prior to 26.7.2, as noted in the security round‑up here.

Beyond the two headline issues, the update resolves three further weaknesses identified in the advisory, including CVE-2026-12564 and CVE-2026-66780, which together raise the overall risk profile of the platform. While the latter two are tracked in Red Hat’s security database, they are resolved in the Keycloak build because the project bundles certain third‑party libraries. The combined patches eliminate paths for token exfiltration and man‑in‑the‑middle attacks inside service meshes that depend on Keycloak‑issued tokens.

As of the advisory date, no public exploitation of CVE-2026-18963 has been observed, and the project’s threat intelligence feeds show no associated intrusion attempts. Nevertheless, the ease of reproducing the bypass in a lab environment means that weaponised exploits could appear quickly, especially given the high value of identity providers as pivot points for broader network intrusions. Security teams should treat the flaw as actively exploitable until proven otherwise.

Administrators should first confirm the current Keycloak version running in their environment and upgrade to 26.7.2 as soon as practicable, following the vendor’s upgrade guide. After applying the patch, they ought to audit password reset logs for abnormal spikes or repeated requests targeting the same account, which could indicate probing activity. Enforcing multi‑factor authentication on all privileged accounts adds a layer of protection even if passwords are reset, and limiting OIDC client registration to known, vetted parties reduces the surface for CVE-2026-15571 style abuse.

Subscribing to the Keycloak security mailing list ensures receipt of future advisories without delay, while monitoring Red Hat’s CVE notifications helps catch any related library vulnerabilities that might affect downstream deployments. Finally, placing the Keycloak endpoint behind a network segmentation boundary and enforcing strict TLS termination limits the chance that an attacker can intercept or manipulate reset tokens in transit.

Intelligence briefing updated Aug 21, 2026

CVE-2026-66780 9.9 CVE-2026-12564 9.6 CVE-2026-18963 9.1 CVE-2026-15571 7.3
Root sourcewww.keycloak.org
Timeline Coverage

Swipe to explore timeline