CVE-2026-18963Patch

CRITICALCVSS 9.1 · CRITICAL

Exploitation observed; activity peaked at 28 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link. This can result in the attacker gaining full control over target user accounts by directly setting new credentials.

8.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-640

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Threat summary

  • Active exploitation appears in 7 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 86 mentions across 21 observed days

What's happening

  • Active exploitation reported across 7 signals
  • Exploit tool or code specified in 12 signals
  • PoC mentioned or linked in 19 signals
  • Patch or workaround mentioned in 43 signals
  • Technical details provided in 69 signals
  • Disclosure: 17 classified signals
  • Peaked 16d ago at 28 mentions (2026-08-24); latest day: 1
  • 86 total mentions across 21 days

Deep dive

Activity timeline86 mentions / 21d
07142128Mentions · 2026-08-19: 1Mentions · 2026-08-20: 1Mentions · 2026-08-21: 4Mentions · 2026-08-23: 3Mentions · 2026-08-24: 28Mentions · 2026-08-25: 27Mentions · 2026-08-26: 5Mentions · 2026-08-27: 1Mentions · 2026-08-31: 1Mentions · 2026-09-01: 1Mentions · 2026-09-04: 1Mentions · 2026-09-06: 1Mentions · 2026-09-07: 1Mentions · 2026-09-08: 3Mentions · 2026-09-09: 2Mentions · 2026-09-11: 1Mentions · 2026-09-18: 1Mentions · 2026-09-22: 1Mentions · 2026-09-23: 1Mentions · 2026-09-24: 1Mentions · 2026-09-29: 1PoC Mentioned / Linked · 2026-08-21: 2PoC Mentioned / Linked · 2026-08-23: 1PoC Mentioned / Linked · 2026-08-24: 5PoC Mentioned / Linked · 2026-08-25: 4PoC Mentioned / Linked · 2026-09-06: 1PoC Mentioned / Linked · 2026-09-07: 1PoC Mentioned / Linked · 2026-09-08: 3PoC Mentioned / Linked · 2026-09-09: 1PoC Mentioned / Linked · 2026-09-11: 1Exploit Tool / Code · 2026-08-21: 2Exploit Tool / Code · 2026-08-24: 1Exploit Tool / Code · 2026-08-25: 5Exploit Tool / Code · 2026-09-06: 1Exploit Tool / Code · 2026-09-07: 1Exploit Tool / Code · 2026-09-08: 2Active Exploitation · 2026-08-24: 1Active Exploitation · 2026-08-25: 2Active Exploitation · 2026-08-26: 1Active Exploitation · 2026-08-27: 1Active Exploitation · 2026-09-09: 1Active Exploitation · 2026-09-22: 1Patch / Workaround · 2026-08-20: 1Patch / Workaround · 2026-08-21: 1Patch / Workaround · 2026-08-23: 2Patch / Workaround · 2026-08-24: 11Patch / Workaround · 2026-08-25: 17Patch / Workaround · 2026-08-26: 4Patch / Workaround · 2026-08-27: 1Patch / Workaround · 2026-08-31: 1Patch / Workaround · 2026-09-01: 1Patch / Workaround · 2026-09-04: 1Patch / Workaround · 2026-09-09: 2Patch / Workaround · 2026-09-18: 1Technical Details · 2026-08-19: 1Technical Details · 2026-08-20: 1Technical Details · 2026-08-21: 3Technical Details · 2026-08-23: 3Technical Details · 2026-08-24: 22Technical Details · 2026-08-25: 23Technical Details · 2026-08-26: 4Technical Details · 2026-08-27: 1Technical Details · 2026-08-31: 1Technical Details · 2026-09-01: 1Technical Details · 2026-09-04: 1Technical Details · 2026-09-06: 1Technical Details · 2026-09-07: 1Technical Details · 2026-09-08: 2Technical Details · 2026-09-09: 2Technical Details · 2026-09-11: 1Technical Details · 2026-09-22: 108-1908-2108-2408-2608-3109-0409-0709-0909-1809-2309-29
Signal classification6 categories
Patch
3441.0%
Disclosure
1720.5%
PoC
1214.5%
General
89.6%
Exploit
78.4%
Active Exploitation
56.0%
Referenced assets50 URLs
By indicator
Classification over time
DateTotalLabels
2026-08-191
Disclosure1
2026-08-201
Disclosure1
2026-08-214
General1Patch1PoC2
2026-08-233
Patch2PoC1
2026-08-2428
Active Exploitation1Disclosure7Exploit1General3Patch11PoC5
2026-08-2527
Active Exploitation1Disclosure5Exploit2General4Patch13PoC2
2026-08-265
Disclosure2Exploit1Patch2
2026-08-271
Active Exploitation1
2026-08-311
Patch1
2026-09-011
Patch1
2026-09-041
Patch1
2026-09-061
Exploit1
2026-09-071
Exploit1
2026-09-083
Exploit1PoC2
2026-09-092
Active Exploitation1Patch1
2026-09-111
Disclosure1
2026-09-181
Patch1
2026-09-221
Active Exploitation1
Full discourse20 posts
  • H4x0r.DZ 🇰🇵@h4x0r_dz
    PoC

    Keycloak is vulnerable to a critical unauthenticated account takeover (CVE-2026-18963) I reproduced the bug locally; interesting one (power of LLM, I think) https://github.com/keycloak/keycloak/issues/51833 https://t.co/QfUjdxpx28

    Post summary

    An individual has reproduced a critical unauthenticated account takeover in Keycloak (CVE-2026-18963) and shared a GitHub link to the reproduction, but no exploit code, active exploitation, patch, or false‑positive claim is mentioned.

    1614871.0K684131.7K
    83.6K followersView on X
  • Dhiyaneshwaran@DhiyaneshDK
    PoC

    🚨 CVE-2026-18963 - Keycloak < 26.7.2 - Unauthenticated Account Takeover via Reset-Credentials Bypass Nuclei Template - https://github.com/projectdiscovery/nuclei-templates/pull/16995/changes Reference: https://github.com/keycloak/keycloak/issues/51833 #hackwithautomation #bugbounty #keycloak https://t.co/3bt2oakew9

    Post summary

    Keycloak releases before 26.7.2 are vulnerable to unauthenticated account takeover (CVE‑2026‑18963). A Nuclei detection template and a GitHub issue provide the PoC and reference details.

    473245838441.0K
    4.9K followersView on X
  • Yunus Emre Öztaş@ynsmroztas
    Exploit

    CVE-2026-18963 · Keycloak (self-hosted) Forgot password → unscoped tryAnotherWay → stale execution leak → UPDATE_PASSWORD without email click → ATO. Scanner + shell: https://github.com/ynsmroztas/KeySniper Authorized testing only. #BugBounty #InfoSec #AppSec #bugbountytip #bugbountytips #infosec #recon

    Post summary

    The post announces code for a functional Keycloak exploit for CVE‑2026‑18963, providing a scanner and shell via GitHub, but makes no claims of wild attacks or available patches.

    448129221835.5K
    8.0K followersView on X
  • Andrew Gömez@red_darkin
    General

    Hoy después de ver varias personas indicando que fueron capaz de reproducir el CVE-2026-18963 relacionado con keycloak, decidí con la ayuda de mi buen amigo Claude y la verdad es que da miedo, como ahora es tan fácil reproducir un bug sin que la PoC haya sido publicada 😱 https://t.co/TsqDcph184

    Post summary

    The tweet notes that CVE‑2026‑18963 (Keycloak) can be easily reproduced by multiple users without a published PoC, but offers no details on the vulnerability, exploitation, patching, or active attacks.

    318125817034.9K
    576 followersView on X
  • Rıdvan Yağlı@ridvanyagli
    Exploit

    🔴 Siber güvenlik araştırmacısı Yunus Emre Öztaş tarafından, Keycloak'taki CVE-2026-18963 (CVSS 9.1 – Kritik) hesap ele geçirme açığı için KeySniper adlı scanner ve post-ATO interaktif shell aracı yayınlandı. Araç: https://github.com/ynsmroztas/KeySniper ⚠️ Yalnızca yetkili güvenlik testlerinde kullanılmalıdır.

    Post summary

    The author released the KeySniper scanner and shell tool for CVE-2026-18963, a critical Keycloak account‑takeover flaw, providing functional exploit code but no patch or evidence of in‑the‑wild exploitation.

    136220419717.0K
    2.4K followersView on X
  • Nicolas Krassas@Dinosn
    Exploit

    CVE-2026-18963 — Keycloak reset-credentials bypass → unauthenticated account takeover https://github.com/snizi/cve-2026-18963-Exploit

    Post summary

    This post announces CVE‑2026‑18963, a Keycloak reset‑credentials bypass allowing unauthenticated account takeover, and links to a GitHub repository that provides exploit code, confirming the vulnerability and its exploitation capability.

    159121313515.0K
    161.9K followersView on X
  • The Hacker News@TheHackersNews
    Disclosure

    ‼️ A critical Keycloak flaw could let attackers take over any account. CVE-2026-18963 lets an unauthenticated attacker reset a user’s password without the emailed action token, including for admin accounts. Read more: https://thehackernews.com/2026/08/critical-keycloak-password-reset-flaw.html

    Post summary

    Keycloak vulnerability CVE-2026-18963 permits unauthenticated reset of any user’s password, potentially enabling account takeover, including admin accounts.

    64831817566.9K
    2.4M followersView on X
  • Giuseppe `N3mes1s`@N3mes1s
    PoC

    CVE-2026-18963: Keycloak reset-credentials flow: unauthenticated account takeover CWE-640 https://www.pruva.dev/reproductions/REPRO-2026-00337 #pruva

    Post summary

    The post announces CVE‑2026‑18963, an unauthenticated Keycloak account takeover flaw (CWE‑640), and provides a link to a reproducible PoC.

    1320105766.4K
    13.5K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    Patch

    A Keycloak account takeover flaw, CVE-2026-18963, lets attackers reset any user's password with no email verification. Update to 26.7.2 now. #Keycloak #AccountTakeover #CVE #IAM #InfoSec #RedHat http://securityonline.info/keycloak-account-takeover-cve-2026-18963/

    Post summary

    A Keycloak account takeover flaw (CVE-2026-18963) lets attackers reset passwords without email verification; users are advised to update to version 26.7.2 to remediate the issue.

    12611096112.5K
    13.0K followersView on X
  • FOFA@fofabot
    Disclosure

    ⚠️⚠️ CVE-2026-18963 (CVSS 9.1): Unauthenticated account takeover in Keycloak via password-reset flow bypass — any account including admins can be reset 🔗FOFA Link: https://en.fofa.info/result?qbase64=YXBwPSJLRVlDTE9BSy3ouqvku73orqTor4Hns7vnu58i 🎯111.5K Results are found on http://en.fofa.info in the past year. FOFA Query: app="KEYCLOAK-身份认证系统" 🔖Refer: https://thehackernews.com/2026/08/critical-keycloak-password-reset-flaw.html #OSINT #FOFA #CyberSecurity #Vulnerability

    Post summary

    The post announces a new Keycloak vulnerability, CVE-2026-18963, with a CVSS of 9.1 that enables unauthenticated attackers to reset any account via a password‑reset flow bypass.

    027088338.5K
    14.8K followersView on X
  • Dark Web Intelligence@DailyDarkWeb
    Patch

    🚨 Critical Keycloak Vulnerability Enables Unauthenticated Account Takeover Red Hat has disclosed CVE-2026-18963, a critical vulnerability affecting the reset-credentials flow in the keycloak-services component used by Red Hat Build of Keycloak. * CVE: CVE-2026-18963 * Severity: CRITICAL * CVSS: 9.1/10 * CWE: CWE-640 — Weak Password Recovery Mechanism * Attack vector: Network * Attack complexity: Low * Privileges required: None * User interaction: None The vulnerability results from improper state validation within Keycloak's reset-credentials authentication flow. An unauthenticated remote attacker can potentially force the password-reset process for a target account WITHOUT requiring the victim to click the expected email verification link. Successful exploitation can allow the attacker to directly establish new credentials and gain full control of the targeted user account. ⚠️ Why This Matters: Keycloak is an identity and access management platform. Compromising an identity account can therefore have consequences beyond a single application, particularly where Keycloak provides centralized authentication or SSO for multiple services. 🛡️ Mitigation: Red Hat recommends upgrading to a fixed version as soon as possible. If immediate upgrading is not possible, Red Hat recommends temporarily disabling "Forgot password" across ALL realms: Realm Settings → Login → Forgot password → Off ⚠️ Analyst Note: This should receive immediate attention from organizations running affected Red Hat Build of Keycloak deployments. The combination of remote exploitation, no authentication requirement, low attack complexity and no required victim interaction makes the vulnerability particularly concerning. At the time of checking, NVD lists the Red Hat CNA score of 9.1 but has not yet provided its own NVD CVSS assessment. Source: Red Hat Product Security https://access.redhat.com/security/cve/cve-2026-18963 NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-18963 #DDW #CyberSecurity #Keycloak #RedHat #CVE #Vulnerability #IAM #ThreatIntelligence

    Post summary

    Red Hat disclosed CVE‑2026‑18963, a critical Keycloak reset‑credentials flaw that allows unauthenticated password resets; the advisory advises upgrading or disabling the “Forgot password” feature as mitigation.

    0210793511.9K
    205.8K followersView on X
  • Vikas Anil Sharma@VikzSharma
    PoC

    Just reproduced the critical CVE-2026-18963 - a Keycloak account takeover vulnerability. Pretty wild time to be doing security research. Really creative exploit. 🙌 to the reporter! It works with both response_type=code with PKCE and the implicit flow (response_type=id_token), since the bug is in the reset-credentials flow, not the OAuth authorization flow.

    Post summary

    The author confirms they have reproduced the Keycloak CVE‑2026‑18963 account‑takeover vulnerability, detailing its impact on both authorization flows, but does not provide exploit code, patch information, or evidence of active exploitation.

    48062606.7K
    2.1K followersView on X
  • IT-Connect.fr@ITConnect_fr
    Patch

    🛑 Avis à tout ceux qui utilisent Keycloak Cette nouvelle faille critique permet de pirater un compte via la fonction de mot de passe oublié. A patcher d'urgence. Tous les détails ici : - https://www.it-connect.fr/keycloak-cve-2026-18963-faille-critique-mot-de-passe-oublie/ #infosec #keycloak https://t.co/cfTaavO1jJ

    Post summary

    The post announces a critical Keycloak vulnerability (CVE‑2026‑18963) that enables account takeover through the forgot‑password mechanism, urging urgent patching.

    216145378.7K
    11.7K followersView on X
  • ThreatWire@ThreatWire_
    Patch

    🚨 CRITICAL: CVE-2026-18963 (CVSS 9.1) is an unauthenticated Keycloak account takeover vulnerability. An attacker can abuse the password-reset flow to take over any user account without authentication or clicking the verification email. 🔴 Update to 26.7.2, 26.6.6 or 26.4.15 LTS. 🔗 https://github.com/keycloak/keycloak/issues/51833 #Keycloak #CVE #AccountTakeover #CyberSecurity

    Post summary

    The post highlights a critical Keycloak vulnerability (CVE-2026-18963) and urges users to upgrade to specific patched versions to remediate the risk.

    05051237.7K
    1.6K followersView on X
  • Andrew Gömez@red_darkin
    PoC

    https://github.com/Red-Darkin/CVE-2026-18963-keycloak PoC

    Post summary

    The provided GitHub link points to a proof‑of‑concept for CVE‑2026‑18963 in Keycloak, with no indications of active exploitation, patches, detailed technical data, or false positive claims.

    02026272.3K
    576 followersView on X
  • dbugs@ptdbugs
    PoC

    A PoC/exploit has been discovered for vulnerability CVE-2026-18963 Vendor: Red Hat Product: Red Hat build of Keycloak 26.4 Description: A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link. This can result in the attacker gaining full control over target user accounts by directly setting new credentials. Link: https://github.com/snizi/cve-2026-18963-exploit #dbugs_vuln

    Post summary

    A PoC/exploit code has been released for CVE-2026-18963, exposing a flaw in Keycloak’s password reset flow that permits unauthenticated attackers to force password changes and fully control target accounts.

    06032132.4K
    3.6K followersView on X
  • CERT@certlv
    Patch

    ‼️Brīdinājums! Red Hat izstrādātajā identitātes piekļuves pārvaldības risinājumā KeyCloak ir atklāta kritiska ievainojamība CVE-2026-18963 (CVSS - 9.1). 🛡️Aicinām atjaunināt Keycloak uz laboto versiju - 26.7.2, 26.4.15, 26.6.6 vai jaunāku. ℹ️ Vairāk: https://cert.lv/lv/2026/08/kritiska-ievainojamiba-red-hat-keycloak https://t.co/VVURpU3yK8

    Post summary

    The advisory flags a critical vulnerability in Red Hat Keycloak (CVE-2026-18963) and recommends applying specific patched versions.

    01102353.7K
    5.7K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-18963 - critical 🚨 Keycloak < 26.7.2 - Unauthenticated Account Takeover via Reset-Credentials Bypass > Keycloak versions prior to 26.7.2, 26.6.6, and 26.4.15 contain a flaw in the reset-cr... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-18963 @pdnuclei #...

    Post summary

    The tweet announces a critical CVE affecting Keycloak versions before 26.7.2, describing an unauthenticated account takeover via reset‑credentials bypass and indicating that updating to 26.7.2 is the solution.

    1302261.4K
    1.3K followersView on X
  • dbugs@ptdbugs
    PoC

    A PoC/exploit has been discovered for vulnerability CVE-2026-18963 Vendor: Red Hat Product: Red Hat build of Keycloak Description: A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link. This can result in the attacker gaining full control over target user accounts by directly setting new credentials. Link: https://github.com/snizi/cve-2026-18963-exploit #dbugs_vuln

    Post summary

    The post announces a discovered PoC for CVE-2026-18963 in Red Hat Keycloak, details the unauthenticated reset‑password flaw, and links to GitHub exploit code.

    1511672.0K
    3.6K followersView on X
  • Previdian@PrevidianCyber
    Active Exploitation

    We're starting to see exploitation attempts for Keycloak Force Password Reset (CVE-2026-18963) against one of our Keycloak sensors in South Africa. The attacker IP is located in the US - 65.87.7[.]125 Looks like a custom tool, not Nuclei, using "kcpwn" string in multiple places https://t.co/FrInk52W8v

    Post summary

    The tweet reports observed exploitation attempts for CVE-2026-18963 (Keycloak Force Password Reset) against a sensor in South Africa, attributed to a custom tool identified by the 'kcpwn' string originating from a US IP address.

    1411742.3K
    131 followersView on X

Explore more