So Keycloak put 26.7.5 on the feed, dated September 30, 2026. We flagged it Important as a security fix. Recency wants the calm opener: patch release, fourteen CVE ids, upgrade to Quarkus 3.33.4, here is a migration guide. Fine. Those are the lines people paste into a status channel when they skim an IAM tag.
The line that matters, to the best of my understanding, is CVE-2026-16103 (GHSA-v7m3-vpqr-6m6p). It is an incomplete fix for CVE-2026-9798. Brute-force protection checks were added to the Client-Initiated Backchannel Authentication (CIBA) initiation handler, but they were left off the token redemption handler. An attacker with valid client credentials can still redeem a previously started, user-approved CIBA request after the account has been locked for brute-force protection, and get access and refresh tokens for that locked user. The lockout looked closed at start. The redemption path stayed open.
That is the partner ticket shape. Someone already thought CIBA lockout was patched. Then a locked account still minting tokens shows up in logs, and the prior CVE number on the ticket is not enough. 26.7.5 closes the redemption gap. Scope is installs that use CIBA with confidential clients and brute-force protection enabled. If you do not run CIBA, this specific path is not your fire. If you do, treat the incomplete prior fix as the reason this patch is not optional.
There are sibling security rows in the same note that are easy to over-paste. CVE-2026-88770: Device Authorization Grant also issued tokens to brute-force-locked accounts (same family as the CIBA incomplete fix). CVE-2026-89298: a confidential client secret could be disclosed to the view-clients role through Client Registration GET. CVE-2026-18211: the secure-client-uris localhost exception accepted localhost-prefixed attacker domains. Plus host/group policy matching bugs, SAML Redirect Binding parameter pollution, introspection JWT leakage, and dependency bumps (OWASP HTML sanitizer, Freemarker, BouncyCastle FIPS). Kind of easy to dump the whole CVE list into a partner email and sound thorough. Kind of useless when the open question is "did our CIBA lockout actually stick after the last patch."
I keep almost filing Keycloak under "IAM patch train, ignore until Red Hat errata." Kind of the wrong habit when you sell into teams that run CIBA or device grant against Keycloak and treat brute-force lockout as a hard stop. Tracking product change here means reading past the fourteen-CVE opener and asking which line changes a partner ticket. Let's say the talking point is not "26.7.5 shipped security fixes." It is CIBA token redemption still issued tokens for a brute-force-locked account after the incomplete CVE-2026-9798 fix (and 26.7.5 closes that redemption path), then yes mention the device-grant sibling and the view-clients secret leak. We pull it into a uniform entry shape at /sources/keycloak.updates. Same JSON as everything else. Recency still wants the CVE list. Recency is not the CIBA redemption gap.