TL;DR what: Red Hat and the Keycloak project patched CVE-2026-18963, an improper state...

Keycloak CVE-2026-18963 could let unauthenticated attackers skip the emailed action token and reset any user's password.

TL;DR what: Red Hat and the Keycloak project patched CVE-2026-18963, an improper state...