Keycloak Fixes Critical CVE-2026-18963 Password Reset Flaw Allowing Unauthenticated Account Takeover
Keycloak has corrected a critical vulnerability, CVE-2026-18963, that allows a remote unauthenticated attacker to force a password reset for any user and take over the account. The priority is to update to the fixed versions or, if that is not possible, disable the Forgot password feature in all realms.
Keycloak, one of the most widely deployed products in corporate environments for identity and access management (IAM), has closed a critical vulnerability that opens the door to account takeover without authentication. The flaw, registered as CVE-2026-18963 and carrying a CVSS 3.1 score of 9.1, affects the reset-credentials flow and permits a remote attacker to complete a user password change without the usual email verification step.
The weakness stems from incorrect state validation inside the authentication flow. In practical terms, the system may accept a sequence of steps that should remain blocked until the user confirms the link sent by email. The result is a bypass: the attacker skips the verification phase and reaches the password change screen or endpoint directly, with the ability to set a new password and later access the account as the legitimate owner.
The most sensitive scenario occurs when the attacker targets administrative accounts. With that control, the attacker can modify policies, create users, assign roles, or alter configurations that affect applications integrated with Keycloak. The CVSS metric accurately reflects the risk: network attack vector, low complexity, no prior privileges, and no user interaction required. The impact focuses on confidentiality and integrity, while availability is not directly affected.
Upstream patches have been released in Keycloak 26.7.2 dated 19 August 2026. For Red Hat Build of Keycloak (RHBK), fixes are provided through updates in the 26.4 and 26.6 branches, specifically versions 26.4.15 and 26.6.6. As of 24 August 2026, Red Hat reports no known exploitation in the wild and no verified public exploit.
For organizations unable to apply updates immediately, the clearest mitigation is to disable the Forgot password recovery option. This setting must be applied realm by realm, so administrators should verify that the feature is disabled in every realm, especially in environments with multiple realms for subsidiaries, customers, or internal applications.
After applying the patch or mitigation, auditing remains essential. Reviewing login events and credential change logs for privileged accounts helps detect anomalous password resets and limits the scope if an attacker attempted to exploit the exposure window. In IAM systems, such a flaw can affect the entire connected ecosystem.
Related articles
Top Cybersecurity Stories: SharePoint Exploits Warned by US Authorities, Citrix and WordPress Flaws Lead Weekly Rankings
Security NEXT has published its weekly ranking of the most viewed articles from September 27 to October 3, 2026, highlighting critical vulnerability disclosures and confirmed exploitation cases. US authorities issued warnings about active exploitation of five vulnerabilities affecting SharePoint and WordPress. Citrix NetScaler received multiple vulnerability advisories with two flaws already confirmed as exploited in the wild. Apple released iOS 26.7.1 to address vulnerabilities potentially used in targeted attacks against specific individuals. Other notable incidents include a personal data breach at Times Car car-sharing service and a ransomware attack impacting Keio Electric Railway operations.
Google Releases Chrome Update Fixing 11 Vulnerabilities Including Critical WebGL Flaw
Google has issued an update for its Chrome browser that addresses 11 security vulnerabilities across Windows, macOS, and Linux platforms. The release includes Chrome 154.0.8037.98 and 154.0.8037.97 for Windows and macOS, along with version 154.0.8037.97 for Linux. One vulnerability, CVE-2026-103628, received a Critical rating due to an out-of-bounds memory write in WebGL that was originally reported in August. Nine additional issues rated High severity affect components such as FileSystem, Compositing, Skia, FedCM, SVG, MediaStream, and WebRTC, including a buffer overflow tracked as CVE-2026-103631. The update also resolves a type confusion flaw in the V8 scripting engine and one Medium-severity issue. Google plans a gradual rollout over the coming days and weeks.
Browser Built on Mistakes: How Real-World Attacks Shaped Modern Browser Defenses
Browser security features such as process isolation, sandboxing, and restrictions on code execution were not designed in isolation but evolved directly in response to concrete attacks over more than a decade. Early threats like malicious Flash advertisements in 2015 demonstrated how a single compromised banner could compromise an entire system, prompting the industry to phase out plugins entirely. Later discoveries, including the Spectre vulnerability, forced browsers to implement stricter site isolation and timing-attack mitigations that remain in place today. Session hijacking and malicious browser extensions further drove the adoption of stronger cookie protections and permission models. BI.ZONE analysts trace this history through specific incidents to show why current architectures prioritize separation of sites into distinct processes. The resulting design reduces the blast radius of any single exploit and continues to adapt as new attack classes emerge.
cKEV Index Launches to Prioritize Vulnerabilities as AI Accelerates Exploit Development
CyberOK has introduced the open cKEV Index, a catalog of high-priority vulnerabilities ranked by the Urgent Patch Score (UPS) methodology. The index incorporates timelines of events such as exploit publication, proof-of-concept releases, and confirmed attacks to help organizations prioritize patching under resource constraints. It addresses the growing gap between rapid AI-assisted vulnerability discovery and slower remediation processes at both vendors and customers. Examples from Anthropic reports highlight how threat actors used AI agents for reconnaissance, code analysis, and exploit development against Android apps and web applications. Microsoft and Oracle have publicly linked increased vulnerability findings and larger patch releases to AI tooling. The UPS framework defines progressive phases from Radar to Emergency/IR, allowing teams to act on strong signals without waiting for full confirmation. An open version of the catalog is now available with detailed event histories for Urgent Patch and Emergency stages.