Red Hat Product Security Update Advisory (CVE-2026-18963)
Aug 26 2026
A security update has been released to address a vulnerability in a Red Hat product.
The affected product is the Red Hat build of Keycloak.
The vulnerability, identified as CVE-2026-18963, is an account compromise vulnerability caused by bypassing the password reset procedure in the Red Hat build of Keycloak.
Affected Versions include Red Hat build of Keycloak version 26.4 Prior to 26.4.15 And version 26.6 Prior to 26.6.6.
A Vulnerability Patch for this vulnerability has been released in the latest update, and users of this product should update to the latest patched versions, 26.4.15 Or 26.6.6.
For reference, security advisories RHSA-2026:56519, RHSA-2026:56520, RHSA-2026:56523, and RHSA-2026:56524 have been issued.