Keycloak CVE-2026-18963 could let unauthenticated attackers skip the emailed action token and reset any user's password. Red Hat and the Keycloak project have released patches to address a critical security flaw in the open-source identity and access management server that could allow an unauthenticated remote attacker to take over any user account by forcing a passwor... [4111 chars]