CyberHighConfirmedAccelerating
8.3
Critical Keycloak vulnerability CVE-2026-18963 enables unauthenticated account takeover
The Hacker News·about 11 hours ago
Threat actors are actively exploiting two critical vulnerabilities in the miniOrange SAML 2.0 SSO plugin, allowing unauthorized administrative access via forged SAML responses. The scope of successful compromises remains unquantified, posing a significant risk to organizations relying on the plugin for identity management.