Thehackerwire CVE-2026-23552: Critical Vulnerability in Keycloak Component
Article Content
Browse articles
CVE-2026-23552 identifies a critical vulnerability in the KeycloakSecurityPolicy of the Apache Camel Keycloak component. This flaw allows a Cross-Realm Token Acceptance Bypass, where JWT tokens from one Keycloak realm are accepted by a policy configured for a different realm, compromising tenant isolation. Affected users are advised to upgrade to Apache Camel version 4.18.0 to mitigate this issue.
Ask AI about this cluster
Answers cite the sources they use
Updated 190d ago How this analysis works
Timeline
2026-02-09
First public PoC released
2026-02-23
CVE-2026-23552 published
2026-02-24
Article published detailing the vulnerability
More articles in this cluster (2)
Following this threat?
Track CVE-2026-23552 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical GitLab CVE-2026-85706 Exploited; Microsoft Issues Record 974 Patches A critical CVE-2026-85706 path-traversal vulnerability in GitLab (CVSS 10.0) was exploited in the wild just hours after its disclosure on September 12, 2026. Microsoft released its largest-ever patch batch, addressing 974 vulnerabilities, including several actively exploited Windows flaws. The GitLab flaw allows…