Blog · 3 posts
#cves
- News · Aug 24, 2026Keycloak password reset flaw let anyone skip the email token and take over any account
CVE-2026-18963 is improper state validation in Keycloak's reset-credentials flow. A crafted request jumped the authentication session straight to the password-update step, no verification token needed. CVSS 9.1, fixed in 26.7.2.
- News · Aug 21, 2026Microsoft patched a CVSS 10.0 Entra ID flaw, then corrected the exploitation flag from yes to no
CVE-2026-69836 was an unauthenticated deserialization flaw in Entra ID scoring a perfect 10.0. Microsoft fixed it service-side with no customer action, but first published it marked as exploited, then reversed that a day later.
- News · Aug 19, 2026NetScaler ships a critical authentication bypass affecting Gateway and AAA virtual servers
CVE-2026-19490 (CVSS 9.3) bypasses authentication on NetScaler ADC and Gateway appliances running a Gateway or AAA virtual server, with a SAML action configured on current builds. Fixed in 14.1-73.32 and 13.1-63.21.