Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
4 / 4 results
criticalbug_reportVulnerabilityCritical Keycloak flaw allows unauthenticated account takeover via password reset
Keycloak identity and access management server: upstream versions prior to 26.7.2; Red Hat build of Keycloak (RHBK) 26.4 prior to 26.4.15 and 26.6 prior to 26.6.6. All realms with "Forgot password" feature enabled are vulnerable.
criticalbug_reportVulnerabilityMicrosoft Entra ID deserialization flaw exploited; already patched
Microsoft Entra ID (formerly Azure Active Directory) cloud-based identity and access management platform. All versions prior to Microsoft's server-side patch.
criticalbug_reportVulnerabilityMicrosoft patches critical Entra ID RCE flaw (CVE-2026-69836, CVSS 10.0)
Microsoft Entra ID (formerly Azure Active Directory), all versions. Cloud-based identity and access management service. Microsoft has already deployed server-side mitigations; no customer action required.
criticalbug_reportVulnerabilityRed Hat Keycloak password-reset flaw enables account takeover
Red Hat build of Keycloak, specific versions not disclosed in source. Vulnerability exists in the password-reset flow mechanism.