Apply the patches released by Red Hat and the Keycloak project immediately. Administrators should update their Keycloak installations to the latest patched versions to prevent exploitation. Review access controls and monitor for unusual password reset activity.
Quick answers
What is CVE-2026-18963?
Apply the patches released by Red Hat and the Keycloak project immediately. Administrators should update their Keycloak installations to the latest patched versions to prevent exploitation. Review access controls and monitor for unusual password reset activity.
How severe is CVE-2026-18963?
critical, CVSS 9.1
Is CVE-2026-18963 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-18963 be mitigated?
Apply the patches released by Red Hat and the Keycloak project immediately. Administrators should update their Keycloak installations to the latest patched versions to prevent exploitation. Review access controls and monitor for unusual password reset activity.
CVSS
9.1
Vendor
Red Hat
Published
Sep 30, 2026 · 08:43
Patch
Unknown / not confirmed
Affected products
Keycloak
Mitigation
Apply the patches released by Red Hat and the Keycloak project immediately. Administrators should update their Keycloak installations to the latest patched versions to prevent exploitation. Review access controls and monitor for unusual password reset activity.
Siemens Industrial Edge Management products contain an authentication bypass vulnerability in the Keycloak services component. The flaw allows an unauthenticated remote attacker to force a password reset for any user account without completing email verification, potentially leading to full account compromise. The vulnerability affects Cloud, Pro V1, Pro V2, and Virtual deployment models across multiple version ranges. Siemens has released updated versions and mitigation guidance to address the issue.
Red Hat and the Keycloak project have released patches to address a critical security flaw in the open-source identity and access management server. The vulnerability, tracked as CVE-2026-18963, has a CVSS score of 9.1 and could allow an unauthenticated remote attacker to force a password reset and take over any user account. Patches have been released to mitigate the issue.