Where
-Infinity
0

Red Hat KeycloakImportant: Red Hat build of Keycloak 26.4.14 Images Security Update

Risk 89
First published (updated )

Red Hat KeycloakImportant: Red Hat build of Keycloak 26.6.5 Security Update

Risk 33
Severity
7
First published (updated )

Red Hat KeycloakImportant: Red Hat build of Keycloak 26.6.5 Images Security Update

Risk 33
Severity
7
First published (updated )

Red Hat KeycloakImportant: Red Hat build of Keycloak 26.4.14 Security Update

Risk 90
First published (updated )

Red Hat KeycloakAn incomplete fix for CVE-2026-9689 was identified in Keycloak's RedirectUtils.containsForbiddenOidc…

Risk 5
Severity
1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

redhat Build Of KeycloakKeycloak-services: keycloak-services: saml broker metadata import disables response signature validation

Risk 66
Severity
9.1
First published (updated )

redhat Build Of KeycloakKeycloak-services: keycloak-services: default dcr policy allows role forgery via user property mappers

Risk 60
Severity
8.1
First published (updated )

Red Hat Keycloak 26.7End of life details

First published (updated )

HCL HCL Hive Telco ObservabilityHCL Hive Telco Observability is affected by  a Required directives missing from the CSP .

Risk 59
Severity
8.1
First published (updated )

Red Hat KeycloakA flaw was found in Keycloak. A remote attacker with high privileges, such as a realm administrator …

Risk 19
Severity
4
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Red Hat KeycloakA flaw was found in Keycloak, an open-source identity and access management solution. When a user ac…

Risk 19
Severity
4
First published (updated )

Red Hat KeycloakA flaw was found in Keycloak. When a JSON Web Encryption (JWE) encrypted request object is submitted…

Risk 19
Severity
4
First published (updated )

Red Hat KeycloakA flaw was found in Keycloak. An authenticated user with low privileges can exploit this vulnerabili…

Risk 19
Severity
4
First published (updated )

Red Hat KeycloakOIDC Introspection fails to honor realm-level notBefore revocation policies when a client-level notB…

Risk 19
Severity
4
First published (updated )

Red Hat KeycloakWhen Keycloak is started with `--features-disabled=account,account-api`, the Account REST API is onl…

Risk 19
Severity
4
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Red Hat Keycloak 26.6Reached end of life

EOL
Jul 9, 2026
First published (updated )

Red Hat KeycloakAuthentication / credential-enrollment vulnerability in Keycloak’s handling of ExecuteActionsActionT…

Risk 19
Severity
4
First published (updated )

Red Hat KeycloakXSS

Risk 19
Severity
4
First published (updated )

Red Hat KeycloakCORS header injection vulnerability in Keycloak’s UMA token endpoint. The flaw is caused by reading …

Risk 5
Severity
1
First published (updated )

Red Hat KeycloakThe vulnerability is a UMA policy bypass in the /realms/{realm}/authz/protection/uma-policy/{resourc…

Risk 33
Severity
7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Red Hat KeycloakWhen receiving a POST request on the OpenID Connect token endpoint, Keycloak fails to limit the pass…

Risk 33
Severity
7
First published (updated )

Red Hat KeycloakKeycloak: keycloak: user enumeration via differential error messages

Risk 15
Severity
3.7
EPSS
0.04%
First published (updated )

Red Hat KeycloakSSRF

Risk 19
Severity
4
First published (updated )

redhat Build Of KeycloakKeycloak: keycloak: replay of action tokens via improper handling of single-use entries

Risk 23
Severity
5.3
EPSS
0.04%
First published (updated )

Red Hat KeycloakKeycloak's SingleUseObjectProvider is a global flat key-value store used without type or namespace i…

Risk 19
Severity
4
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

redhat Build Of KeycloakKeycloak: keycloak: privilege escalation via forged authorization codes due to singleuseobjectprovider isolation flaw

Risk 41
Severity
7.4
EPSS
0.04%
First published (updated )

Red Hat KeycloakKeycloak's SingleUseObjectProvider is a global flat key-value store used by multiple features withou…

Risk 33
Severity
7
First published (updated )

Red Hat KeycloakA flaw was found in Keycloak's redirect_uri validation logic. This issue may allow bypassing the all…

Risk 33
Severity
7
First published (updated )

Red Hat KeycloakImportant: Red Hat build of Keycloak 26.4.10 Update

Risk 33
Severity
7
First published (updated )

Red Hat KeycloakImproper Access Control vulnerability in the Account REST API of Keycloak. The flaw is caused by ins…

Risk 19
Severity
4
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203