Articles about security from the Skycloak team.
Microsoft's September 2026 report shows passkey-themed lures driving AiTM and device-code attacks. Here is the Keycloak realm hardening that answers…
CVE-2026-17048 lets a view-only Keycloak admin read the plaintext of a vault-backed rotated client secret. CVSS 5.5, fixed in 26.7.2…
CVE-2026-82968 lets an attacker on the same social provider intercept Keycloak account linking. CVSS 6.4, no patched release yet. What…
CVE-2026-18963 lets an unauthenticated attacker take over any Keycloak account through the reset-credentials flow. CVSS 9.1. Three release lines carry…
CVE-2026-88770 lets Keycloak's device authorization grant redeem tokens for an account brute-force protection already locked. CVSS 6.5, no patch yet.
Keycloak 26.7.3 fixes twenty CVEs across FGAP v2, OIDC and token exchange. What to re-test after you upgrade, and which…
CVE-2026-35563 is scoped to a Keycloak test dependency, not LDAP user federation. Here is what really governs LDAP certificate validation…
Two moderate Keycloak CVEs let admins act outside their permissions on organizations. What they allow, who is affected, and what…
Unit 42 showed a root-compromised Kubernetes node can spoof SPIFFE/SPIRE workload identities via cgroup tricks. Here is what actually breaks,…
Ce que la Loi 25 et la LPRPDE exigent de votre gestion des identités, où vos données doivent résider, et…
Get tutorials, product updates, and Keycloak tips delivered to your inbox.