Security
Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account
The Hacker News·August 24, 2026·1 min read
Red Hat and the Keycloak project released patches for a critical flaw in the open-source identity and access management server, CVE-2026-18963, rated 9.1 on the CVSS scale. The vulnerability could allow an unauthenticated remote attacker to take over any user account by forcing a password reset. Users are urged to apply the updates immediately to mitigate risk.
Read at The Hacker NewsDaily crypto arcade
Read the news, then play it.
Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.
