Cyber security Keycloak password reset flaw lets attackers take over any account Rated CVSS 9.1, CVE-2026-18963 in Keycloak's password reset flow lets unauthenticated attackers skip email checks and take over any account. Data Today Security Desk · Aug 25, 2026