PSA: Critical unauthenticated account takeover vulnerability in #Keycloak - allows resetting arbitrary users‘ passwords. Update to 26.7.2 immediately or disable password reset. Tracked as CVE-2026-18963. #infosec
Good to see that some publications are finally picking up the critical #Keycloak CVE. A bit surprising that it took more than 5 days.