Last 7 days
0
Features: 0
Changes: 0
Fixes: 0
Deprecations: 0
Open-source identity and access management for applications and services.
Latest Keycloak changelog updates, official release notes, breaking changes, security patches, pricing changes, and developer reactions in one product feed.
Follow this Keycloak release-notes page to spot useful features, risky migrations, noisy announcements, and source links before they hit your backlog.
Changes.Watch links back to official changelog and release-note sources so summaries stay easy to verify.
Use channels to follow groups of tools around a stack, workflow, or topic.
Rolling windows show how many product updates landed in the last 7, 30, 90, and 365 days, grouped by existing changelog semantics.
0
1
4
5
Added preview SCIM API for automated user provisioning, multi‑cluster HA without external caches, and step‑up authentication for SAML clients.
Multiple critical security fixes addressing CVEs (group admin escalation, filesystem path disclosure, XSS, token misuse, privilege escalation, authorization bypass, JWT algorithm confusion)
Addressed numerous security vulnerabilities (CVE‑2026‑4800, 2026‑4874, 2026‑37977, 2026‑7500, 2026‑42581, 2026‑8922, 2026‑8830, 2026‑9088, 2026‑9087, 2026‑9802, 2026‑9794, 2026‑9791, 2026‑0707, 2026‑9801, 2026‑9704, 2026‑9792) covering c...
Fixed numerous security vulnerabilities (CVE-2026-33871, CVE-2026-33870, CVE-2026-4628, CVE-2026-37980, CVE-2026-5588, CVE-2026-6856, multiple Bouncy Castle CVEs, CVE-2026-7307, CVE-2026-7504, CVE-2026-7571, CVE-2026-7507, CVE-2026-37982...
Fixed two critical security issues (CVE‑2026‑4366 SSRF and CVE‑2026‑4633 user enumeration)