CVE-2025-7365

high
Published 2025-07-10 · Modified 2025-07-30
CVSS v3
7.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:N
CVSS v2
VIR risk
7.1

Description

Keycloak phishing attack via email verification step in first login flow

Predictions

Exploit likelihood
80%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://bugzilla.redhat.com/show_bug.cgi?id=2378852

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://access.redhat.com/security/cve/CVE-2025-7365

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://access.redhat.com/errata/RHSA-2025:12016

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://access.redhat.com/errata/RHSA-2025:12015

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://access.redhat.com/errata/RHSA-2025:11987

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://access.redhat.com/errata/RHSA-2025:11986

Package impact

EcosystemPackageVulnerableFixed
java Mavenorg.keycloak:keycloak-services<26.0.1326.0.13
java Mavenorg.keycloak:keycloak-services>=26.2.0,<26.2.626.2.6

Application impact

VendorProductVersionsFixed
redhatkeycloak-

References

CWEs

CWE-346

Verify integrity in audit chain (admin only). AS-IS.