VORANT. Threat Intelligence Sign in Get the full feed

Multiple Keycloak Vulnerabilities Patched

medium vulnerability technology

Several vulnerabilities in Keycloak versions before 26.6.5, 26.7.1, and 26.4.14 can lead to privilege escalation, DoS, and data confidentiality breaches.

ANSSI (CERT-FR) issued an advisory covering multiple vulnerabilities discovered in Keycloak, the widely-used open-source identity and access management solution. The flaws affect Keycloak versions 26.6.x prior to 26.6.5, 26.7.x prior to 26.7.1, and all versions prior to 26.4.14. Seven CVEs were disclosed alongside corresponding GitHub security advisories published by the Keycloak project on August 6, 2026.

The vulnerabilities collectively enable an attacker to bypass security policies, escalate privileges, cause remote denial of service, and compromise data confidentiality. No indication of active exploitation is provided in this advisory; it is a vendor-coordinated disclosure with patches available. Administrators running affected Keycloak deployments should consult the vendor advisories and apply the corresponding fixes promptly given Keycloak's common role as a centralized authentication provider.

Mentioned in this report

Vulnerabilities CVE-2026-15572CVE-2026-15573CVE-2026-16071CVE-2026-16100CVE-2026-16102CVE-2026-16442CVE-2026-16443

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0976

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free