Overview
- Red Hat
- Red Hat build of Keycloak 26.4
- rhbk/keycloak-operator-bundle
Description
Statistics
- 6 Posts
- 10 Interactions
Fediverse
Note the recently disclosed CVE-2026-18963 for #Keycloak OIDC: https://thehackernews.com/2026/08/critical-keycloak-password-reset-flaw.html . It allows unauthorized users to take over any account on your server.
On the #Slackware #Forgejo instance https://forge.slackware.nl/ I have upgraded Keycloak to 26.7.2 to address this vulnerability.
⚠️ Critical Keycloak flaw enables account takeover
CVE-2026-18963 lets unauthenticated attackers reset any user's password, bypassing email verification.
📰 Critical Keycloak Flaw (CVE-2026-18963) Allows Account Takeover
🚨 CRITICAL FLAW: Keycloak is vulnerable to CVE-2026-18963 (CVSS 9.1), allowing unauthenticated remote attackers to take over any account. Patches are available—update immediately! #Keycloak #Cybersecurity #Vulnerability #CVE #IAM
Geopolitical tensions rise as US-Iran dispute over Strait of Hormuz escalates; UK pledges long-range missile tech to Ukraine. Nvidia increases AI server prices over 15% due to memory costs. Critical Keycloak flaw (CVE-2026-18963) found allowing account takeovers, while Apple warns of mercenary spyware.
⚠️ CRITICAL: Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account
Critical flaw in Keycloak (CVE-2026-18963, CVSS 9.1) allows unauthenticated attackers to reset any user password and take over accounts due to improper state validation in the password recovery flow. Any organization running Keycloak without patches is immediately at risk of account takeover on all…
🤖 AI generated summary
Overview
Description
Statistics
- 6 Posts
- 11 Interactions
Fediverse
⚠️ CRITICAL: CISA orders urgent patching of actively exploited Zimbra flaw
Zimbra Collaboration Suite (ZCS) has a critical unauthenticated RCE vulnerability (CVE-2026-73570) that is actively exploited in the wild. Any organization running ZCS is at immediate risk of full system compromise. CISA has mandated U.S. government agencies patch within three days.
🤖 AI generated summary
CVE-2026-73570: Actively exploited CRITICAL RCE in Zimbra Collaboration Suite <10.1.20 via SNMP command injection. Patch to 10.1.20 now. Watch for suspicious service restarts & files in /opt/zimbra/jetty/webapps/. Details: https://radar.offseq.com/threat/cisa-orders-urgent-patching-of-actively-exploited-zimbra-flaw-b89f77b410f3bb5f #OffSeq #Zimbra #Infosec #RCE
Bluesky
Overview
- Microsoft
- Microsoft Entra
Description
Statistics
- 3 Posts
Fediverse
Mysterien um Microsofts kritisches Sicherheitsloch in Entra ID
Am vorigen Donnerstag macht Microsoft (MS) ein riesiges Trara um eine höchst gefährliche Sicherheitslücke CVE-2026-69836 (Risiko 10 von 10) in Entra ID*. Ein entfernter, nicht autorisierter Angreifer könne durch Ausnutzung dieser Sicherheitslücke beliebigen Programmcode ausführen (RCE). Und die Lücke würde bereits für Angriffe ausgenutzt. Meldungen beispielsweise hier oder hier. Wie die Ausnutzung entdeckt wurde und wer vielleicht betroffen ist, verlautet MS nicht. Einen Tag später zieht MS die Auskunft "wird bereits ausgenutzt" zurück. Hä? Interessant ist auch, dass ... Weiterlesen:
#0day #backdoor #cloud #exploits #identität #Microsoft #sicherheit #unplugMicrosoft #UnplugTrump
Bluesky
Overview
- NetScaler
- ADC
Description
Statistics
- 2 Posts
Bluesky
Overview
- Zscaler
- Client Connector
Description
Statistics
- 1 Post
- 4 Interactions
Fediverse
https://nvd.nist.gov/vuln/detail/CVE-2026-59568
Multiple vulnerabilities on affected versions of Zscaler Client Connector allow remote code execution, giving an unauthenticated, unprivileged user the ability to execute arbitrary code in the ZCC context.
Overview
- UTT
- HiPER 1250GW
Description
Statistics
- 1 Post
- 3 Interactions
Fediverse
CRITICAL: Stack-based buffer overflow (CVE-2026-78169) in UTT HiPER 1250GW v3.2.7-210907-180535. Public exploit code available — no patch yet. Restrict device access & monitor /goform/aspRemoteApConfTempSend traffic. https://radar.offseq.com/threat/cve-2026-78169-stack-based-buffer-overflow-in-utt-hiper-1250gw-b9697a669a575a95 #OffSeq #CVE #Infosec #IoT
Overview
Description
Statistics
- 1 Post
- 2 Interactions
Fediverse
A PostgreSQL vulnerability (CVE-2026-14669, CVSS 8.8) with public PoC exploit code allows remote code execution via to_char. Update now.
#PostgreSQL #CVE202614669 #RCE #HeapOverflow #Database #InfoSec
Overview
Description
Statistics
- 1 Post
- 2 Interactions
Overview
Description
Statistics
- 1 Post
- 2 Interactions
Overview
- phoca.cz
- Phoca Cart extension for Joomla
Description
Statistics
- 1 Post
- 2 Interactions
Fediverse
‼️ CVE PoC Published: CVE-2026-76565 - Reflected XSS in PhocaCart
GitHub: https://github.com/toanln-cov/CVE-2026-76565
A proof-of-concept has been released for CVE-2026-76565, a reflected cross-site scripting (XSS) vulnerability affecting PhocaCart ≤ 6.1.7 for Joomla.
The vulnerability exists in the price_from and price_to filter parameters within the mod_phocacart_filter module. Due to improper output encoding, unauthenticated attackers can craft a malicious URL that injects JavaScript into the page when viewed by a victim.
The PoC demonstrates:
• Reflected XSS through crafted GET parameters
• Exploitation of vulnerable price filter inputs
• Attribute-context injection caused by missing htmlspecialchars() encoding
• No authentication requirement for exploitation
• Affected versions: PhocaCart ≤ 6.1.7
• Fixed version: PhocaCart 6.1.8
💥 No delays. No guessing. No redactions. Get the intel before everyone else with Dark Web Informer.