Mmastodon TechnologyCybersecurity first seen 5 h ago, last 5 h ago, peak #11
Keycloak Kerberos flaw lets network attackers hijack accounts
Original: CVE-2026-95503 Keycloak Kerberos auth bypass, CVSS 6.8. Unpatched. Same-network attacker can spoof the KDC and take over
A newly disclosed vulnerability, CVE-2026-95503, affects Keycloak's Kerberos authentication and carries a CVSS score of 6.8. It remains unpatched. An attacker on the same network can spoof the Kerberos Key Distribution Center and take over user accounts. Security commentators urge administrators to isolate Kerberos traffic or stop using password authentication without SPNEGO protection until a fix is released.
Why now: Security teams are alerting each other to an unpatched authentication bypass that could allow account takeover in exposed deployments.
KeycloakCVE-2026-95503Kerberos
Evidence
API: https://socialmediatrends-api.osmike.com/v1/trends/728178