CVE-2026-18963: #Keycloak arbitrary account takeover via session confusion using simple HTTP requests. 😱
Nice find and (allegedly) not even AI-powered at its core.
A working exploit is publicly available. Given Keycloak's widespread use in critical auth systems, this appears to be flying a bit under the radar so far.
If you run Keycloak, it needs your attention *now*.