logo

Red Hat Keycloak vulnerability CVE-2026-18963: find impacted assets

ID: 6aa62f0e-5658-531b-84b1-3a93065ddcd8

STIX ID: report--6aa62f0e-5658-531b-84b1-3a93065ddcd8

Feed Name: runZero Blog

Threat Score
85/100

Date Published: 2026-08-24

Date Updated: 2026-08-24

Author: Matthew Kienow

...
...

**Red Hat Keycloak — CVE-2026-18963 (Critical, CVSS 9.1):** A flaw in the reset-credentials authentication flow of the keycloak-services component allows a remote, unauthenticated attacker to bypass email verification during password recovery and fully take over user accounts; multiple Red Hat Keycloak 26.4 and 26.6 builds/versions are affected and the advisory provides specific fixed package versions to upgrade to.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.