Multiple vulnerabilities in KeyCloak (June 29, 2026)
Multiple vulnerabilities have been discovered in KeyCloak. Some of them allow an attacker to cause remote arbitrary code execution, privilege escalation, and data confidentiality breaches.
CSIRTS triage
- What
- Multiple vulnerabilities can lead to remote code execution, privilege escalation, and data confidentiality breaches.
- Who is affected
- Users of KeyCloak, specifics not detailed in the advisory.
- Urgency
- Remediation is urgent due to the potential for serious security breaches.
- Action
- Update KeyCloak to the latest version to mitigate these vulnerabilities.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch KeyCloak
Get an email when a new KeyCloak advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0815/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-90860.78% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 53% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-90990.49% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 40% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-98000.63% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 48% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-97950.35% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 28% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-97050.46% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 38% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-97990.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-90830.78% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 53% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-118000.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 22% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-9086 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-9099 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-9800 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-9795 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-9705 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-9799 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-9083 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-11800 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
Recent advisories for KeyCloak
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownNCSC-2026-0326 [1.00] [M/H] Vulnerabilities patched in Keycloakncsc-nl · 2026-08-25
- mediumCVE-2026-79652: A flaw was found in the JWT Bearer authorization grant implementation within the keycloak-serv…nvd · 2026-08-25
- high[NEW] [high] Keycloak: Multiple vulnerabilitiescert-bund · 2026-08-25
- unknownMultiple vulnerabilities in Keycloak (August 25, 2026)cert-fr-avis · 2026-08-25
- mediumCVE-2025-68833: HCL Hive Keycloak IAM Instance is affected by insufficient granularity of access control which…nvd · 2026-08-24
- medium[UPDATE] [medium] Keycloak: Multiple vulnerabilitiescert-bund · 2026-08-19
More from CERT-FR Avis de sécurité
- unknownMultiple vulnerabilities in Keycloak (August 25, 2026)2026-08-25
- unknownMultiple vulnerabilities in Cisco IOS XE (August 25, 2026)2026-08-25
- unknownMultiple vulnerabilities in LibreNMS (August 24, 2026)2026-08-24
- unknownMultiple vulnerabilities in Metabase (August 24, 2026)2026-08-24
- unknownVulnerability in SPIP (August 21, 2026)2026-08-21