セキュリティ対策Lab[verified]@securityLab_jpPatch
The message announces that Keycloak has released patches addressing four critical vulnerabilities identified by the CVE-2026 series.
The Hacker Wire@TheHackerWireDisclosure
The tweet announces a high‑severity flaw in Keycloak that allows control bypass via a valid SAML response from an external IdP, but provides no PoC, exploit, patch, or active exploitation details.
RedPacket Security@RedPacketSecGeneral
The tweet announces CVE-2026-2603, affecting Red Hat's Keycloak 26.2 build, and links to a detailed alert page, with no additional exploitation, patch, or PoC information.
PulsePatch.io@pulsepatchioDisclosure
The article announces that a misconfiguration in Keycloak's disabled SAML Identity Provider could allow unauthorized authentication, urging administrators to review settings.
CVEarity@CVEarityGeneral
The tweet announces CVE‑2026‑2603 with a severity score of 8.1 and a high risk rating, but it does not provide technical details, PoC, exploit code, or mitigation information.
CVE@CVEnewDisclosure
A new Keycloak vulnerability (CVE‑2026‑2603) enables attackers to bypass security controls via a valid SAML response from an external Identity Provider; the text contains technical details of the flaw but no PoC, exploit code, active exploitation, or mitigation.
Autumn Good@autumn_good_35Disclosure
Keycloak 26.5.5 has been released, addressing four CVEs: CVE-2026-3047, CVE-2026-3009, CVE-2026-2603, and CVE-2026-2092.