security1 distinct publisher
Keycloak's forgotten-password flow hands over admin accounts, and the fix is already tagged
CVE-2026-18963 lets an unauthenticated request skip the emailed reset token entirely. Upstream 26.7.2 and four Red Hat errata are out, and the stopgap has to be set realm by realm.
Publishers:thehackernews.com
Reality
- Evidence74
- Adoption42
- Hype gap−8
- Incentives58
- Confidence66