logo

Keycloak Under Siege: Patch Now to Stop Token Theft and Account Takeovers

ID: 44f3c39d-b9f8-5192-92f0-9260ce0dfb2e

STIX ID: report--44f3c39d-b9f8-5192-92f0-9260ce0dfb2e

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-04-06

Date Updated: 2026-04-23

Author: Ddos

...
...

Keycloak released a critical security update (26.5.7) addressing several vulnerabilities—including CVE-2026-3429 (MFA deletion/bypass allowing account takeover), CVE-2026-4636 (UMA policy manipulation allowing issuance of Requesting Party Tokens), CVE-2026-3872 (wildcard redirect abuse enabling access token theft), and CVE-2026-1002 (URI handling flaw causing resource access failures). Organizations using Keycloak are strongly advised to apply the update immediately to prevent account compromise and data exposure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.