Tutorials, deep dives, and best practices from the Skycloak team.
AWS Cognito pricing tracks monthly active users, and enterprise SSO users get a free tier of only 50. Three checks…
MCP OAuth flaw GHSA-qx49-fqc8-xw99: a malicious server could steal client secrets and PKCE verifiers from the MCP Python SDK. Upgrade,…
SSO answers one line of a vendor security review. What reviewers also check: enforced SSO, deprovisioning, sessions, audit logs, and…
CVE-2026-100606 lets anyone who signs in with an invitee's email take over a pending Flowise Enterprise invite. How it works…
SOC 2 Type 1 vs Type 2: Type 1 checks control design on one date, Type 2 checks controls worked…
Storm-3168 (JADEPUFFER) wiped Azure resources with compromised service principals. How the same client secret risk looks on Keycloak, and how…
CVE-2026-96448 is a Keycloak privilege escalation: an FGAP v2 delegated admin assigns a composite role that hides realm-admin. How it…
Keycloak 26.7.4 fixes six CVEs, from a SAML memory leak to impersonation of realm admins. Which reach 26.6 and 26.4,…
CVE-2026-19607: a brokered login whose email matches a Keycloak username shadows that user and locks them out. Fixed in 26.7.4.…
CVE-2026-97176 can let Keycloak issue a token at a lower assurance level than a client's essential acr demands, skipping step-up.…
Get tutorials, product updates, and Keycloak tips delivered to your inbox.