Security News

Cybersecurity news aggregator

🔄
CRITICAL Updates Red Hat Errata

RHSA-2026:56519: Critical: Red Hat build of Keycloak 26.4.15 Images Security Update

  • What: Security update for Red Hat build of Keycloak 26.4.15 images
  • Impact: Critical vulnerabilities fixed in authentication and user management
Read Full Article →

Red Hat Product Errata RHSA-2026:56519 - Security Advisory Issued: 2026-08-18 Updated: 2026-08-18 RHSA-2026:56519 - Security Advisory Overview Updated Images Synopsis Critical: Red Hat build of Keycloak 26.4.15 Images Security Update Type/Severity Security Advisory: Critical Topic New images are available for Red Hat build of Keycloak 26.4.15 and Red Hat build of Keycloak 26.4.15 Operator, running on OpenShift Container Platform Description Red Hat build of Keycloak is an integrated sign-on solution, available as a Red Hat JBoss Middleware for OpenShift containerized image. The Red Hat build of Keycloak for OpenShift image provides an authentication server that you can use to log in centrally, log out, and register. You can also manage user accounts for web applications, mobile applications, and RESTful web services. Red Hat build of Keycloak Operator for OpenShift simplifies deployment and management of Keycloak 26.4.15 clusters. This erratum releases new images for Red Hat build of Keycloak 26.4.15 for use within the OpenShift Container Platform cloud computing Platform-as-a-Service (PaaS) for on-premise or private cloud deployments, aligning with the standalone product release. Security fixes: Unauthenticated account takeover via reset-credentials flow bypass (CVE-2026-18963) Solution Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. Affected Products Red Hat build of Keycloak Text-only Advisories x86_64 Fixes (none) CVEs CVE-2026-13757 CVE-2026-18963 References https://access.redhat.com/security/updates/classification/#critical aarch64 rhbk/keycloak-rhel9@sha256:faf3f6772c31b33f526887927505095a6dd5bd8e507c643ebcc64eea60be56eb rhbk/keycloak-rhel9-operator@sha256:32c3da0c9e63f7a86ae49255fbcf318406bb3e34ee07f1bae7e1dc01c6329efd ppc64le rhbk/keycloak-rhel9@sha256:5ae22f5c60ebeab633caa0ac3e3540402e9d589409513c67c2b1dada998c178d rhbk/keycloak-rhel9-operator@sha256:9b5001e9dde3cd87823988cafd809a5887b296c048e398171e28b1c256de1107 s390x rhbk/keycloak-rhel9@sha256:8918c47378bb686b0894188d6ad578e5ce469def4926c419194703237a2fee3d rhbk/keycloak-rhel9-operator@sha256:b72782f1fbc44144e58f08884b5a6f9a3a49e32c1965a9ce3d01bd6f70e761f8 x86_64 rhbk/keycloak-operator-bundle@sha256:f4df815564fc6801b50dffbbd3e0a421dfd83841c83c22a8e09305eeffdaf687 rhbk/keycloak-rhel9@sha256:696cf024e6bb736260b7a2439cc9e7b3aa05024c8c493ae6e448b224718e464b rhbk/keycloak-rhel9-operator@sha256:b80c873fd9fe1ec85cf4191714a6ea2ac80854b2bdc3781d15811d16692527a0 The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .

Share this article