Founder at Skycloak
Guilliano is the founder of Skycloak and a cloud infrastructure specialist with deep expertise in product development and scaling SaaS products. He discovered Keycloak while consulting on enterprise IAM and built Skycloak to make managed Keycloak accessible to teams of every size.
CVE-2026-100606 lets anyone who signs in with an invitee's email take over a pending Flowise Enterprise invite. How it works…
SOC 2 Type 1 vs Type 2: Type 1 checks control design on one date, Type 2 checks controls worked…
Storm-3168 (JADEPUFFER) wiped Azure resources with compromised service principals. How the same client secret risk looks on Keycloak, and how…
CVE-2026-96448 is a Keycloak privilege escalation: an FGAP v2 delegated admin assigns a composite role that hides realm-admin. How it…
Keycloak 26.7.4 fixes six CVEs, from a SAML memory leak to impersonation of realm admins. Which reach 26.6 and 26.4,…
CVE-2026-19607: a brokered login whose email matches a Keycloak username shadows that user and locks them out. Fixed in 26.7.4.…
CVE-2026-97176 can let Keycloak issue a token at a lower assurance level than a client's essential acr demands, skipping step-up.…
CVE-2026-97177 enables account takeover in Keycloak: a delegated admin denied reset-password can still set passwords via user update. How it…
CVE-2026-97846 lets Keycloak standard token exchange issue an unbound Bearer token for an mTLS-bound client. What it breaks, who is…
CVE-2026-79651 lets anyone exhaust Keycloak heap via a public theme localization endpoint. It is fixed in 26.7.4, 26.6.7 and 26.4.16.…