August 25, 2026
- Keycloak CVE-2026-18963 now has patches. The CVSS 9.1 flaw is improper state validation in the reset-credentials flow in
keycloak-services, allowing an unauthenticated remote attacker to force a password reset and take over any account; a researcher reported reproducing it locally (The Hacker News, Red Hat) (earlier coverage). · Vulnerabilities & Exploits
in The Rogue Agent Staged an Apology, Then Pushed More Malware