Cyber security
Keycloak password reset flaw lets attackers take over any account
CVE-2026-18963 is a critical unauthenticated account takeover in Keycloak's password reset flow, rated CVSS 9.1, letting attackers bypass email verification and set new credentials on any account.