Articles about security from the Skycloak team.
Account takeover (ATO) means an attacker controls a real user's account. How it differs from a breach, the seven entry…
CVE-2026-103884 lets a crafted client certificate steer Keycloak's X.509 CRL loader outside its conf directory. Who is exposed, the real…
Credential stuffing replays leaked username and password pairs against your login. How it differs from brute force, what to watch…
Session hijacking uses a stolen cookie or token, so MFA never fires. How infostealers do it, what limits the damage,…
Better Auth 1.7.7 stops OAuth state values being redeemed as magic-link tokens. What went wrong, how to upgrade, and how…
CVE-2026-5430 let forged JWTs past WSO2 API Manager authentication. Here is how you pin algorithms and fail closed on APIs…
MCP OAuth flaw GHSA-qx49-fqc8-xw99: a malicious server could steal client secrets and PKCE verifiers from the MCP Python SDK. Upgrade,…
Storm-3168 (JADEPUFFER) wiped Azure resources with compromised service principals. How the same client secret risk looks on Keycloak, and how…
CVE-2026-100606 lets anyone who signs in with an invitee's email take over a pending Flowise Enterprise invite. How it works…
CVE-2026-19607: a brokered login whose email matches a Keycloak username shadows that user and locks them out. Fixed in 26.7.4.…
Get tutorials, product updates, and Keycloak tips delivered to your inbox.