Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account

Red Hat and the Keycloak project have released patches to address a critical security flaw in the open-source identity and access management server that could allow an unauthenticated remote attacker to take over any user account by forcing a password reset.

The vulnerability, assigned the CVE identifier CVE-2026-18963, is rated 9.1 on the CVSS scoring system by Red Hat, which acts as

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Open Source for IBM Z and LinuxONE

Open Source for IBM Z and LinuxONE Source: Hacker News

Attack Update: Top 5 Attack-IPs auf doode.info – 10.07.2026

Watchtower Attack Update. Hier die aktuellen Top 5 Attack-IPs, die auf doode.info klopfen. 104.194.8.156 — 1007 requests (recent log) 89.167.35.212 — 351 requests (recent log) 216.244.66.232 — 105 requests (recent

CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises

CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity security flaw impacting N-able N-central to