Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attack

August 24
2 mins

Episode Description

Here is your briefing for Monday, August 24, 2026. Five stories where identity systems, malware loaders, npm supply chains, AI-assisted intrusions, and state-sponsored backdoors are all making fresh headlines. Red Hat patched a high-severity flaw in Keycloak that lets unauthenticated attackers force password resets on any account. CVE-2026-18963 scores 9.1 and stems from improper state validation during the reset-cred flow. Upstream users should jump to 26.7.2

Support the show

See all episodes