Founder at Skycloak
Guilliano is the founder of Skycloak and a cloud infrastructure specialist with deep expertise in product development and scaling SaaS products. He discovered Keycloak while consulting on enterprise IAM and built Skycloak to make managed Keycloak accessible to teams of every size.
Keycloak has shipped experimental CIMD support since 26.6 behind the cimd flag. Here is the client policy that lets Claude…
CVE-2026-17048 lets a view-only Keycloak admin read the plaintext of a vault-backed rotated client secret. CVSS 5.5, fixed in 26.7.2…
Okta, Ping and JumpCloud all shipped agentic IAM in the last three weeks. Here is what those launches actually add,…
Keycloak 26.7 promotes its native SCIM API to preview behind the scim-api flag. It handles CRUD, PATCH and filtering, but…
CVE-2026-88770 lets Keycloak's device authorization grant redeem tokens for an account brute-force protection already locked. CVSS 6.5, no patch yet.
CVE-2026-18963 lets an unauthenticated attacker take over any Keycloak account through the reset-credentials flow. CVSS 9.1. Three release lines carry…
CVE-2026-82968 lets an attacker on the same social provider intercept Keycloak account linking. CVSS 6.4, no patched release yet. What…
Keycloak 26.7.3 fixes twenty CVEs across FGAP v2, OIDC and token exchange. What to re-test after you upgrade, and which…
CVE-2026-35563 is scoped to a Keycloak test dependency, not LDAP user federation. Here is what really governs LDAP certificate validation…
Two moderate Keycloak CVEs let admins act outside their permissions on organizations. What they allow, who is affected, and what…