Book a demo
Products & ServicesEvent: August 31, 2026

FORTBRIDGE identified and reported a vulnerability CVE-2026-18963 affecting Keycloak 26.0.0 through 26.7.1, which allows unauthenticated account takeover via the Forgot password flow without requiring email access or user interaction.

Published

Signal category

Products & Services

Quote

CVE-2026-18963 - unauthenticated account takeover of any Keycloak user via the 'Forgot password' flow.

FORTBRIDGE team

Company

FORTBRIDGE

FORTBRIDGE – Leading IT Security Services in London | Cybersecurity, Penetration Testing, Red Teaming and Cloud Security

Industry
Computer and Network Security
Location
London, GB
Company size
5 employees

Every engagement led by consultants with 10-20 years of offensive security experience. No juniors. No outsourcing. No bait-and-switch. FORTBRIDGE is a CREST and DESC accredited penetration testing firm based in London, UK. We specialise in identifying and mitigating vulnerabilities across web applications, APIs, mobile apps, cloud environments, and AI/LLM systems. What sets us apart: every assessment is executed start-to-finish by senior consultants holding elite certifications (OSCP, OSWE, CRTO, CRTL, AWS/Azure/GCP). You communicate directly with the tester - no account managers, no go-betweens. Our research has been featured in The Guardian, Market Watch, The Register, and more. Our Services Include: ➤ Web Application Penetration Testing ➤ Mobile & API Penetration Testing ➤ Cloud Security Assessment ➤ Red Teaming ➤ Network Penetration Testing ➤ Security Architecture Review ➤ Phishing Simulations ➤ LLM Security Testing ➤ White Box Penetration Testing As a family-run business, security is in our blood. We work with organisations from startups to FTSE 100 companies. For more information, contact FORTBRIDGE today.

Founded 2020

Customize signals for your business.

Know everything happening across the B2B world, and act on the company movements that matter to you.

© 2026 SeedOpsCompany intelligence.

SeedOps.

FORTBRIDGE identified and reported a vulnerability CVE-2026-18963 affecting Keycloak 26.0.0 through 26.7.1, which allows unauthenticated account takeover via the Forgot password flow without requiring email access or user interaction. | SeedOps