Keycloak Under Siege: Patch Now to Stop Token Theft and Account Takeovers
ID: 44f3c39d-b9f8-5192-92f0-9260ce0dfb2e
STIX ID: report--44f3c39d-b9f8-5192-92f0-9260ce0dfb2e
Feed Name: securityonline.info
Keycloak released a critical security update (26.5.7) addressing several vulnerabilities—including CVE-2026-3429 (MFA deletion/bypass allowing account takeover), CVE-2026-4636 (UMA policy manipulation allowing issuance of Requesting Party Tokens), CVE-2026-3872 (wildcard redirect abuse enabling access token theft), and CVE-2026-1002 (URI handling flaw causing resource access failures). Organizations using Keycloak are strongly advised to apply the update immediately to prevent account compromise and data exposure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
