German government CERT advisories reported a Keycloak vulnerability that can allow attackers to bypass security measures in deployments using the identity and access management platform. The issue was published in multiple advisories, indicating continued tracking and notification of the same security weakness affecting Keycloak environments.
Organizations using Keycloak should review the affected product versions and vendor guidance tied to the advisories, assess whether authentication or access-control protections could be circumvented, and prioritize remediation. Because Keycloak is commonly used for single sign-on and identity federation, a successful bypass could weaken protections around user authentication and protected applications.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
dCERT published advisory 2026-1309 for a Keycloak vulnerability described as allowing bypass of security measures. The reference provides no additional technical details or remediation information.
dCERT published advisory 2026-1213 concerning a Keycloak vulnerability described as allowing bypass of security measures. Based on the references alone, this appears to be a later advisory or update related to the same issue area.
dCERT published advisory 2026-0550 for a Keycloak vulnerability that could allow attackers to bypass security measures. No additional technical details or remediation information are provided in the reference content.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
dcert.de
Open sourcedcert.de
Open sourcedcert.de
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.