Overview
- Red Hat
- Red Hat build of Keycloak 26.4
- rhbk/keycloak-operator-bundle
Description
Statistics
- 6 Posts
- 14 Interactions
Fediverse
Note the recently disclosed CVE-2026-18963 for #Keycloak OIDC: https://thehackernews.com/2026/08/critical-keycloak-password-reset-flaw.html . It allows unauthorized users to take over any account on your server.
On the #Slackware #Forgejo instance https://forge.slackware.nl/ I have upgraded Keycloak to 26.7.2 to address this vulnerability.
Geopolitical tensions rise as US-Iran dispute over Strait of Hormuz escalates; UK pledges long-range missile tech to Ukraine. Nvidia increases AI server prices over 15% due to memory costs. Critical Keycloak flaw (CVE-2026-18963) found allowing account takeovers, while Apple warns of mercenary spyware.
⚠️ Critical Keycloak flaw enables account takeover
CVE-2026-18963 lets unauthenticated attackers reset any user's password, bypassing email verification.
📰 Critical Keycloak Flaw (CVE-2026-18963) Allows Account Takeover
🚨 CRITICAL FLAW: Keycloak is vulnerable to CVE-2026-18963 (CVSS 9.1), allowing unauthenticated remote attackers to take over any account. Patches are available—update immediately! #Keycloak #Cybersecurity #Vulnerability #CVE #IAM
⚠️ CRITICAL: Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account
Critical flaw in Keycloak (CVE-2026-18963, CVSS 9.1) allows unauthenticated attackers to reset any user password and take over accounts due to improper state validation in the password recovery flow. Any organization running Keycloak without patches is immediately at risk of account takeover on all…
🤖 AI generated summary
Overview
Description
Statistics
- 5 Posts
- 11 Interactions
Fediverse
⚠️ CRITICAL: CISA orders urgent patching of actively exploited Zimbra flaw
Zimbra Collaboration Suite (ZCS) has a critical unauthenticated RCE vulnerability (CVE-2026-73570) that is actively exploited in the wild. Any organization running ZCS is at immediate risk of full system compromise. CISA has mandated U.S. government agencies patch within three days.
🤖 AI generated summary
CVE-2026-73570: Actively exploited CRITICAL RCE in Zimbra Collaboration Suite <10.1.20 via SNMP command injection. Patch to 10.1.20 now. Watch for suspicious service restarts & files in /opt/zimbra/jetty/webapps/. Details: https://radar.offseq.com/threat/cisa-orders-urgent-patching-of-actively-exploited-zimbra-flaw-b89f77b410f3bb5f #OffSeq #Zimbra #Infosec #RCE
Bluesky
Overview
Description
Statistics
- 2 Posts
- 1 Interaction
Fediverse
CISA warned that the CVE-2026-21962 Oracle flaw with a CVSS 10 score is actively exploited in the wild. Patch Oracle Fusion Middleware systems now.
Here's a summary of recent geopolitical, technology, and cybersecurity news:
Geopolitical: The US has launched "Operation Economic Outcast" against Iran (Aug 25) and plans 7.5% tariffs on Chinese goods over excess manufacturing capacity before a September summit (Aug 25).
Technology: Google is reorganizing DeepMind and acquired Spirit Airlines' data for AI model development (Aug 24). Fujitsu is trialing AI for construction process and risk management (Aug 25).
Cybersecurity: CISA added an Oracle HTTP Server vulnerability (CVE-2026-21962) to its Known Exploited Vulnerabilities Catalog (Aug 24). Critical GitLab (CVE-2026-19478) and Cisco vulnerabilities (CVSS 10.0) are under active exploitation (Aug 24).
Overview
- Zscaler
- Client Connector
Description
Statistics
- 1 Post
- 6 Interactions
Fediverse
https://nvd.nist.gov/vuln/detail/CVE-2026-59568
Multiple vulnerabilities on affected versions of Zscaler Client Connector allow remote code execution, giving an unauthenticated, unprivileged user the ability to execute arbitrary code in the ZCC context.
Overview
Description
Statistics
- 1 Post
- 2 Interactions
Fediverse
A PostgreSQL vulnerability (CVE-2026-14669, CVSS 8.8) with public PoC exploit code allows remote code execution via to_char. Update now.
#PostgreSQL #CVE202614669 #RCE #HeapOverflow #Database #InfoSec
Overview
Description
Statistics
- 1 Post
- 2 Interactions
Overview
Description
Statistics
- 1 Post
- 2 Interactions
Overview
- phoca.cz
- Phoca Cart extension for Joomla
Description
Statistics
- 1 Post
- 2 Interactions
Fediverse
‼️ CVE PoC Published: CVE-2026-76565 - Reflected XSS in PhocaCart
GitHub: https://github.com/toanln-cov/CVE-2026-76565
A proof-of-concept has been released for CVE-2026-76565, a reflected cross-site scripting (XSS) vulnerability affecting PhocaCart ≤ 6.1.7 for Joomla.
The vulnerability exists in the price_from and price_to filter parameters within the mod_phocacart_filter module. Due to improper output encoding, unauthenticated attackers can craft a malicious URL that injects JavaScript into the page when viewed by a victim.
The PoC demonstrates:
• Reflected XSS through crafted GET parameters
• Exploitation of vulnerable price filter inputs
• Attribute-context injection caused by missing htmlspecialchars() encoding
• No authentication requirement for exploitation
• Affected versions: PhocaCart ≤ 6.1.7
• Fixed version: PhocaCart 6.1.8
💥 No delays. No guessing. No redactions. Get the intel before everyone else with Dark Web Informer.
Overview
- wedevs
- Dokan Pro
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
دليل شامل لثغرة SQL Injection في إضافة Dokan Pro
ثغرة حقن SQL في إضافة Dokan Pro (CVE-2026-12077)1. الملخص التنفيذي ثغرة من نوع SQL Injection تعتمد على التأخير الزمني (Time-Based Blind SQL Injection) تم اكتشافها في إضافة Dokan Pro لأنظمة ووردبريس، والتي تُستخدم لإنشاء متاجر متعددة البائعين (Multi-Vendor Marketplaces). تؤثر على جميع الإصدارات حتى 5.0.4، وتسمح لمهاجم غير […]Overview
- PixelYourSite Professional
- Boost
- boost
Description
Statistics
- 1 Post
- 1 Interaction