H4x0r.DZ 🇰🇵[verified]@h4x0r_dzPoC
An individual has reproduced a critical unauthenticated account takeover in Keycloak (CVE-2026-18963) and shared a GitHub link to the reproduction, but no exploit code, active exploitation, patch, or false‑positive claim is mentioned.
Yunus Emre Öztaş[verified]@ynsmroztasExploit
The post announces code for a functional Keycloak exploit for CVE‑2026‑18963, providing a scanner and shell via GitHub, but makes no claims of wild attacks or available patches.
Rıdvan Yağlı[verified]@ridvanyagliExploit
The author released the KeySniper scanner and shell tool for CVE-2026-18963, a critical Keycloak account‑takeover flaw, providing functional exploit code but no patch or evidence of in‑the‑wild exploitation.
Nicolas Krassas[verified]@DinosnExploit
This post announces CVE‑2026‑18963, a Keycloak reset‑credentials bypass allowing unauthenticated account takeover, and links to a GitHub repository that provides exploit code, confirming the vulnerability and its exploitation capability.
Giuseppe `N3mes1s`[verified]@N3mes1sPoC
The post announces CVE‑2026‑18963, an unauthenticated Keycloak account takeover flaw (CWE‑640), and provides a link to a reproducible PoC.
FOFA[verified]@fofabotDisclosure
The post announces a new Keycloak vulnerability, CVE-2026-18963, with a CVSS of 9.1 that enables unauthenticated attackers to reset any account via a password‑reset flow bypass.
Dark Web Intelligence[verified]@DailyDarkWebPatch
Red Hat disclosed CVE‑2026‑18963, a critical Keycloak reset‑credentials flaw that allows unauthenticated password resets; the advisory advises upgrading or disabling the “Forgot password” feature as mitigation.
Vikas Anil Sharma[verified]@VikzSharmaPoC
The author confirms they have reproduced the Keycloak CVE‑2026‑18963 account‑takeover vulnerability, detailing its impact on both authorization flows, but does not provide exploit code, patch information, or evidence of active exploitation.