Category

security

Articles about security from the Skycloak team.

security

What Is Account Takeover (ATO)? How SaaS Teams Detect and Prevent It

Account takeover (ATO) means an attacker controls a real user's account. How it differs from a breach, the seven entry…

Guilliano Molaire Guilliano Molaire 14 min read
security

Keycloak CVE-2026-103884: X.509 CRL Path Traversal When CRL Checking Is On

CVE-2026-103884 lets a crafted client certificate steer Keycloak's X.509 CRL loader outside its conf directory. Who is exposed, the real…

Guilliano Molaire Guilliano Molaire 12 min read
security

What Is Credential Stuffing? Vs Brute Force, and How to Stop It

Credential stuffing replays leaked username and password pairs against your login. How it differs from brute force, what to watch…

Guilliano Molaire Guilliano Molaire 7 min read
security

Session Hijacking: Why MFA Doesn’t Save a Stolen Session

Session hijacking uses a stolen cookie or token, so MFA never fires. How infostealers do it, what limits the damage,…

Guilliano Molaire Guilliano Molaire 8 min read
security

Better Auth 1.7.7: OAuth State vs Magic-Link Tokens

Better Auth 1.7.7 stops OAuth state values being redeemed as magic-link tokens. What went wrong, how to upgrade, and how…

Guilliano Molaire Guilliano Molaire 11 min read
security

CVE-2026-5430: WSO2 JWT Bypass and Your Keycloak APIs

CVE-2026-5430 let forged JWTs past WSO2 API Manager authentication. Here is how you pin algorithms and fail closed on APIs…

Guilliano Molaire Guilliano Molaire 13 min read
security

MCP Python SDK OAuth Flaw: Pin the Issuer on Keycloak

MCP OAuth flaw GHSA-qx49-fqc8-xw99: a malicious server could steal client secrets and PKCE verifiers from the MCP Python SDK. Upgrade,…

Guilliano Molaire Guilliano Molaire 12 min read
security

JADEPUFFER and Storm-3168: Retire Static Keycloak Secrets

Storm-3168 (JADEPUFFER) wiped Azure resources with compromised service principals. How the same client secret risk looks on Keycloak, and how…

Guilliano Molaire Guilliano Molaire 12 min read
security

CVE-2026-100606: Flowise SSO Invite Takeover and IdP Checks

CVE-2026-100606 lets anyone who signs in with an invitee's email take over a pending Flowise Enterprise invite. How it works…

Guilliano Molaire Guilliano Molaire 10 min read
security

CVE-2026-19607: Keycloak Username Takeover and Account Lockout

CVE-2026-19607: a brokered login whose email matches a Keycloak username shadows that user and locks them out. Fixed in 26.7.4.…

Guilliano Molaire Guilliano Molaire 11 min read

Stay ahead on identity & security

Get tutorials, product updates, and Keycloak tips delivered to your inbox.

© 2026 Skycloak. All Rights Reserved. Design by Yasser Soliman