@cloud_iam_com

A fully managed Keycloak solution with 99.95% SLA, ISO 27001 certification, 24/7 expert support — all hosted in Europe to ensure compliance and data sovereignty

Internet
Joined July 2019
Keycloak 26.7.4 released yesterday, with 5 High CVEs. Here's a short summary of each of them 👇
1
2
111
CVE-2026-90997:  When using MySQL or MariaDB as the database in stateless mode, the replay protection mechanism for single-use security artifacts fails to detect reuse due to a row-count semantics mismatch between the database driver's default configuration and 🧵
1
2
42
Keycloak's application logic. An attacker who intercepts one of these short-lived artifacts can replay it to obtain unauthorized access.
2
10
What does it technically mean to deploy on 5 different cloud providers? Each cloud has its own quirks, services, maintenance behaviours, and failure modes. So our team had to build up expertise to handle day to day operations on all five of those platforms.
1
1
26
To accomplish that goal we rely on multi-AZ and multi-region deployments, to give us the resiliency we need. If those safeguards are not enough, our tooling and disaster recovery playbooks allow us to move the affected deployment to another region easily.
1
1
8
We're planning to write more about this on our blog, if you have questions, let us know, they might end up answered in the post.
1
3
Cloud-IAM let you choose exactly where your Keycloak deployments runs on 5 cloud providers and 70+ regions. We take care of the operational complexity, you choose where. Because "managed" should not mean you don't make infrastructure decision. eu1.hubs.ly/H0xzv4s0
2
42
Keycloak 26.7 is out and available to Cloud-IAM user for two weeks now. It's a one-click upgrade, check our migration guide for more details on what's new. eu1.hubs.ly/H0xqS490
3
101
Open source is open technically, closed experientially. You can read every line. You still can't shape it without writing code. Designers aren't excluded by policy. They're excluded by architecture. eu1.hubs.ly/H0vvmXn0
3
42
Open source won the infrastructure war. But it stayed closed to anyone who doesn't code. Designers can't fork a flow. UX can't PR a finding. The only valid contribution is still a commit. We built open source for transparency, not participation. eu1.hubs.ly/H0vvndl0
1
24
Our CTO Luis at Keycloak Dev Day 2026: how we run multi-region Keycloak with mTLS at scale. Cert rotation, CRL management, trust chain observability across regions. The kind of stuff you only fully grasp in prod. "Scaling Trust" talk is live 👇 eu1.hubs.ly/H0vvhlR0
31
Self-managed Keycloak. One click to deploy not for management. That's the part most teams don't calculate before they start. The three engineers you'll need to keep it alive aren't on the invoice. We broke down what actually costs in terms of team. eu1.hubs.ly/H0vvg-G0
32
You picked Keycloak. Solid choice. But who's going to keep it running? Your team. Most CTOs discover this after the first incident. We broke down what it actually costs in terms of team effort for every model: On-Prem, IaaS, Marketplace, PaaS, SaaS eu1.hubs.ly/H0vvgp90
41