Blog

Insights on Identity, Security & Keycloak

Tutorials, deep dives, and best practices from the Skycloak team.

security

CVE-2026-88770: Keycloak’s Device Flow Can Still Issue Tokens for a Locked Account

CVE-2026-88770 lets Keycloak's device authorization grant redeem tokens for an account brute-force protection already locked. CVSS 6.5, no patch yet.

Guilliano Molaire Guilliano Molaire 8 min read
security

CVE-2026-18963: The Keycloak Password Reset Takeover, and Which Versions Fix It

CVE-2026-18963 lets an unauthenticated attacker take over any Keycloak account through the reset-credentials flow. CVSS 9.1. Three release lines carry…

Guilliano Molaire Guilliano Molaire 10 min read
security

CVE-2026-82968: Hardening Keycloak First-Broker Login While the Fix Is Pending

CVE-2026-82968 lets an attacker on the same social provider intercept Keycloak account linking. CVSS 6.4, no patched release yet. What…

Guilliano Molaire Guilliano Molaire 8 min read
security

Keycloak 26.7.3 Security Fixes: A Self-Hosted Patch Checklist

Keycloak 26.7.3 fixes twenty CVEs across FGAP v2, OIDC and token exchange. What to re-test after you upgrade, and which…

Guilliano Molaire Guilliano Molaire 9 min read
security

Keycloak LDAP Certificate Validation: What CVE-2026-35563 Actually Affects

CVE-2026-35563 is scoped to a Keycloak test dependency, not LDAP user federation. Here is what really governs LDAP certificate validation…

Guilliano Molaire Guilliano Molaire 7 min read
security

CVE-2026-16072 and CVE-2026-18201: Two Keycloak Organization Permission Gaps

Two moderate Keycloak CVEs let admins act outside their permissions on organizations. What they allow, who is affected, and what…

Guilliano Molaire Guilliano Molaire 7 min read
Articles

Stateless MCP: What the 2026-07-28 Spec Changes for Tool Builders

MCP went stateless in the 2026-07-28 spec: no initialize handshake, no Mcp-Session-Id. Here is what changes for MCP servers and…

Guilliano Molaire Guilliano Molaire 11 min read
best-practices

SPIFFE/SPIRE Workload Identity: What a Compromised Node Actually Breaks

Unit 42 showed a root-compromised Kubernetes node can spoof SPIFFE/SPIRE workload identities via cgroup tricks. Here is what actually breaks,…

Guilliano Molaire Guilliano Molaire 11 min read
Authentication Error Handling: User Experience and Security Balance
Tutorials

Keycloak Authentication Error Handling: Custom Error Pages

Customize Keycloak error pages, handle OAuth/OIDC errors in your app, and configure brute force protection for secure, user-friendly authentication.

Guilliano Molaire Guilliano Molaire 11 min read
guides

How Many Nines Does Your Keycloak SLA Actually Need?

Four nines vs five nines for authentication: what each SLA tier really costs, which Keycloak architecture delivers it, and when…

Guilliano Molaire Guilliano Molaire 5 min read

Stay ahead on identity & security

Get tutorials, product updates, and Keycloak tips delivered to your inbox.

© 2026 Skycloak. All Rights Reserved. Design by Yasser Soliman