Red Hat Keycloak vulnerability CVE-2026-18963: find impacted assets
ID: 6aa62f0e-5658-531b-84b1-3a93065ddcd8
STIX ID: report--6aa62f0e-5658-531b-84b1-3a93065ddcd8
Feed Name: runZero Blog
Threat Score
**Red Hat Keycloak — CVE-2026-18963 (Critical, CVSS 9.1):** A flaw in the reset-credentials authentication flow of the keycloak-services component allows a remote, unauthenticated attacker to bypass email verification during password recovery and fully take over user accounts; multiple Red Hat Keycloak 26.4 and 26.6 builds/versions are affected and the advisory provides specific fixed package versions to upgrade to.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
