CVE-2026-18963 is improper state validation in Keycloak's reset-credentials flow. A crafted request jumped the authentication session straight to the password-update step, no verification token needed. CVSS 9.1, fixed in 26.7.2.