<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[🔴 Critical: Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account]]></title><description><![CDATA[<p dir="auto">Patches are now available for a critical vulnerability in <strong>Keycloak</strong>, the open-source identity and access management platform. The flaw, tracked as <strong><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-18963" target="_blank" rel="noopener noreferrer nofollow ugc">CVE-2026-18963</a></strong> and rated <strong>9.1 on the CVSS scale</strong> by Red Hat, could allow an unauthenticated remote attacker to force a password reset and subsequently take over any user account within the system.</p>
<p dir="auto">The issue lies in the password reset flow, where a lack of proper validation or authentication checks permits malicious actors to initiate the process without valid credentials. Because Keycloak is widely deployed as a central authentication hub for enterprises, a successful exploit could grant an attacker unauthorized access to connected applications and sensitive data.</p>
<p dir="auto">The coordinated patches were released by both the Keycloak project and Red Hat. Administrators are strongly urged to take immediate action to mitigate the risk:</p>
<ul>
<li>Apply the latest updates to Keycloak servers without delay.</li>
<li>Review access logs for any suspicious password reset requests or unexpected account lockouts.</li>
<li>Consider enforcing additional verification steps for password reset operations, such as OTP or email confirmation, if not already configured.</li>
</ul>
<p dir="auto">Given the severity and the unauthenticated nature of the attack, proper patching is the primary defense. Ensure your deployment is updated to a fixed version as soon as possible.</p>
<p dir="auto">Source: <a href="https://thehackernews.com/2026/08/critical-keycloak-password-reset-flaw.html" target="_blank" rel="noopener noreferrer nofollow ugc">The Hacker News</a></p>
<p dir="auto">Has your team already applied the patches, or are you waiting on a maintenance window to roll these out?</p>
]]></description><link>https://xploitlk.com/topic/92/critical-critical-keycloak-password-reset-flaw-could-let-unauthenticated-attackers-take-over-any-account</link><generator>RSS for Node</generator><lastBuildDate>Sat, 05 Sep 2026 13:27:48 GMT</lastBuildDate><atom:link href="https://xploitlk.com/topic/92.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 25 Aug 2026 06:30:20 GMT</pubDate><ttl>60</ttl></channel></rss>