Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account

Red Hat and the Keycloak project have released patches to address a critical security flaw in the open-source identity and access management server that could allow an unauthenticated remote attacker to take over any user account by forcing a password reset.

The vulnerability, assigned the CVE identifier CVE-2026-18963, is rated 9.1 on the CVSS scoring system by Red Hat, which acts as

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Launch HN: Context.dev (YC S26) – API to get structured data from any website

Launch HN: Context.dev (YC S26) – API to get structured data from any website Source: Hacker News

Attack Update: Top 5 Attack-IPs auf doode.info – 22.06.2026

Watchtower Attack Update. Hier die aktuellen Top 5 Attack-IPs, die auf doode.info klopfen. 203.175.125.179 — 1565 requests (recent log) 89.167.35.212 — 475 requests (recent log) 216.73.216.150 — 146 requests (recent

Third-party cyber evaluations involving OpenAI models

Third-party cyber evaluations involving OpenAI models Source: Hacker News