<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:media="http://search.yahoo.com/mrss/"><channel><title>Cve-2026-18963 on it-learn.io | IT, Networking &amp; Cybersecurity Blog</title><link>https://blog.it-learn.io/tags/cve-2026-18963/</link><description>Recent content in Cve-2026-18963 on it-learn.io | IT, Networking &amp; Cybersecurity Blog</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 24 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://blog.it-learn.io/tags/cve-2026-18963/index.xml" rel="self" type="application/rss+xml"/><item><title>Keycloak Account Takeover — CVE-2026-18963 CVSS 9.1</title><link>https://blog.it-learn.io/posts/2026-08-24-keycloak-account-takeover-cve-2026-18963-cvss-9-1/</link><pubDate>Mon, 24 Aug 2026 00:00:00 +0000</pubDate><author>it-learn.io</author><guid>https://blog.it-learn.io/posts/2026-08-24-keycloak-account-takeover-cve-2026-18963-cvss-9-1/</guid><description>CVE-2026-18963 (CVSS 9.1) lets remote attackers reset any Keycloak password without authentication — every federated app behind it is exposed. Also today: Iran-linked hackers shut down a UK power plant for four days in the first confirmed nation-state OT attack causing sustained Western energy downtime, and Spring Framework&amp;rsquo;s 10x vulnerability surge forces a remediation capacity conversation.</description><media:content url="https://blog.it-learn.io/images/posts/newsletter-default/banner.png" medium="image"/></item><item><title>Keycloak Account-Takeover RCE — CVE-2026-18963</title><link>https://blog.it-learn.io/identity/2026-08-24-identity-keycloak-account-takeover-rce-cve-2026-18963/</link><pubDate>Mon, 24 Aug 2026 00:00:00 +0000</pubDate><author>it-learn.io</author><guid>https://blog.it-learn.io/identity/2026-08-24-identity-keycloak-account-takeover-rce-cve-2026-18963/</guid><description>CVE-2026-18963 is a CVSS 9.1 unauthenticated password-reset flaw in Keycloak that lets attackers hijack any account without credentials or MFA bypass. SynkLoader malware uses fake Windows lock screens delivered through Teams phishing to harvest credentials in real time. Microsoft ships a new admin toggle to block external bots from meetings. Plus: device-code phishing survives passkeys, and 9,300 AWS keys remain active on GitHub.</description><media:content url="https://blog.it-learn.io/images/posts/newsletter-default/banner.png" medium="image"/></item></channel></rss>