Tutorials, deep dives, and best practices from the Skycloak team.
CVE-2026-97176 can let Keycloak issue a token at a lower assurance level than a client's essential acr demands, skipping step-up.…
CVE-2026-97177 enables account takeover in Keycloak: a delegated admin denied reset-password can still set passwords via user update. How it…
CVE-2026-79651 lets anyone exhaust Keycloak heap via a public theme localization endpoint. It is fixed in 26.7.4, 26.6.7 and 26.4.16.…
TrustSink turns a rogue Entra external MFA provider into a password trap after an admin compromise. What it needs, why…
Login is one of the biggest sections of a vendor security questionnaire. What the SSO, MFA, access review, audit log…
Connect Cursor to the Skycloak MCP server at mcp.skycloak.io, sign in with browser OAuth, and manage Keycloak clusters, realms, apps…
Use Claude Code or Cursor to review Keycloak realm exports safely: redact secrets, catch PKCE and audience mistakes, and keep…
CVE-2026-95503 lets an adjacent-network attacker spoof the KDC when Keycloak does Kerberos password authentication without SPNEGO. No fixed release yet.
Okta shipped Resource Access Certifications for AI agents on 22 September 2026. What the control does, and how to run…
Get tutorials, product updates, and Keycloak tips delivered to your inbox.