
Keycloak 26.6.3 Release Notes — 16 CVEs Patched, Including Privilege Escalation and SSRF
Keycloak 26.6.3 fixes 16 CVEs: privilege escalation via token exchange, SSRF on the OIDC endpoint, refresh token reuse after restart, and more. If you run Keycloak in production, update now.





