
Keycloak 26.6.2: 16 CVEs patched — several exploitable without authentication
Keycloak 26.6.2 fixes 16 CVEs at once, including session fixation in the OIDC login flow, redirect URI validation bypass, and stored XSS. If you run it in production, update now.



