Find notable cyber news and cases, enriched with sources, timelines, and signals.

Keycloak password-reset account takeover flaw (CVE-2026-18963)

Vulnerability
First reported
Last updated
Happening score
H score 31
1 unique sources, 1 articles

Summary

Hide ▲

Patches are available for CVE-2026-18963 in Keycloak, closing a critical password-reset flaw that could let an unauthenticated remote attacker seize any user account, including administrative accounts. The weakness is an improper state validation bug in the reset-credentials flow, where a crafted request can jump straight to password update without the normal email action token. Fixed builds are Keycloak 26.7.2 and Red Hat build of Keycloak 26.4.15 / 26.6.6, with a temporary workaround to disable Forgot password.

Related Happenings

CISA SmarterMail remediation guidance for CVE-2026-24423

Advisory/Mitigation
H score86 First: 06.02.2026 19:16 Last: 06.02.2026 19:16 Sources 1

About this happening: SmarterMail is at the center of a CVE-2026-24423 remediation and exploitation wave: the flaw enables unauthenticated remote code execution in versions prior to Build...

SmarterMail CVE-2026-23760 mass exploitation wave

Exploitation Wave
H score89 First: 27.01.2026 16:09 Last: 27.01.2026 16:09 Sources 1

About this happening: CVE-2026-23760 is being exploited against SmarterMail to bypass authentication on internet-facing mail servers, creating takeover risk across thousands of exposed in...

Timeline

  1. 24.08.2026 14:56 1 articles · 9h ago

    Red Hat patches Keycloak CVE-2026-18963

    Initial Disclosure

    Red Hat and the Keycloak project released patches for CVE-2026-18963, a critical reset-credentials flaw in Keycloak that could let an unauthenticated remote attacker force a password reset and take over any user account, including administrative accounts.

    Show sources
  2. 24.08.2026 14:56 2 articles · 9h ago

    Red Hat says CVE-2026-18963 has no known exploitation and advises disabling Forgot password

    Mitigation Patch Update

    Red Hat said there was no evidence that CVE-2026-18963 had been exploited as of August 24, 2026, and advised affected Keycloak deployments to disable the Forgot password setting across all realms until they can upgrade to a fixed version.

    Show sources