CRITICALAdvisoryAug 24, 2026
Action required
Immediately patch all Keycloak instances to patched versions or disable the 'Forgot password' functionality. Hunt for POST requests to password reset endpoints from unauthenticated sources and monitor for unusual password reset activity in the past 30 days.
Affected products
KeycloakRed Hat
CVE IDs
Linked articles