Two days, two releases, twenty CVE identifiers, and no release note that mentions the other one.

26.7.5 landed September 30 — the fifth point release on the 26.7 line this site has covered since the twenty-CVE batch, in what is now the sixth week of the cadence. Its release notes carry fourteen security fixes. The next morning 26.8.0 shipped — six CVE identifiers (three Keycloak-native, three dependency), zero of which appear in 26.7.5's list. The previous day's note does not say "these fixes are also in tomorrow's release." The next day's note does not say "our five fix items subsume the fourteen you read yesterday." Each document describes its own tag and stops.

Where do you go to resolve the overlap? The advisory databases. That path is dead: the NVD and GHSA entries for this batch — checked at publish time for the CIBA bypass, the device-grant sibling, the IdP mapper escalation, the broker email-verification, the SAML memory leak — list affected versions: Unknown, patched versions: Unknown across the board. A scanner keyed on version ranges returns nothing. An operator who resolves the ambiguity the standard way gets no answer at all.

So this site answered it the way that actually produces an answer: by diffing the tags at code level. Every claim below is a file-level comparison between the 26.7.5 and 26.8.0 trees in the upstream repository, plus ancestor checks of the named fix commits. The method note matters because the conclusion is not what either release note implies.

What the diff says

Every fix in 26.7.5's fourteen-CVE list is present in 26.8.0. Verified by direct file comparison at both tags:

  • The brute-force family — CIBA token redemption (CVE-2026-16103, the incomplete-fix round of CVE-2026-9798) and its device-grant sibling (CVE-2026-88770) — the BruteForceProtector checks sit in CibaGrantType, BackchannelAuthenticationEndpoint, and DeviceGrantType identically at both tags.
  • The client-policy batch — source-host wildcard matching (CVE-2026-18206), source-group path resolution (CVE-2026-18207), the secure-client-uris localhost exception (CVE-2026-18211), name-vs-path group policy resolution (CVE-2026-18203's partial-evaluation family — the relevant providers are byte-identical at both tags) — same code at both.
  • SAML Redirect Binding Parameter Pollution (CVE-2026-18217): KeycloakUriBuilder and BaseSAML2BindingBuilder are byte-identical across both tags. Same for the introspection JWT-claim fix (CVE-2026-18208).
  • The client-secret leak to view-only roles (CVE-2026-89298) and the disabled-client audience persistence (CVE-2026-93999): the fix code (StripSecretsUtils on view-only registration reads; disabled-client checks in audience resolution) is present at both.
  • The dependency rows — FreeMarker 2.3.35, OWASP HTML Sanitizer, BouncyCastle FIPS — pinned at identical versions in both tags' pom.xml.

26.8.0 is a superset of 26.7.5's security content. That part an optimist could have guessed.

The reverse is false, and this is the part the combined notes hide. Two of 26.8.0's Keycloak CVEs have no fixed 26.7.x version at all — not in 26.7.5, not anywhere on the line:

  • CVE-2026-12388 — IdP mapper privilege escalation to realm administrator (Red Hat Bugzilla 2489140). An administrator holding only manage-identity-providers can point an IdP at a server they control and attach a Hardcoded Role mapper targeting realm-admin. The mapper endpoint never checked whether the account managing the IdP had the authority to grant the role it was granting. Delegated administrator walks in; realm administrator walks out. The fix — a proper role-grant validation on mapper create/update — is in IdentityProviderResource at 26.8.0 and absent at 26.7.5 (verified line by line). Community read: if you delegate IdP management to a sub-team — the federation volunteer, the "person who handles the LDAP connection" — that delegation carried this path until 26.8.0.
  • CVE-2026-19608 — same-name groups satisfy path-specific group policies. Group policies evaluating token claims that carry group names rather than paths fell back to an exact-name match, so a claim naming a sibling group with a colliding name satisfied a policy written for a specific path. 26.7.5's tree still carries that exact-name-match code (verified). The 26.8.0 fix resolves name-only claims to top-level groups only, and ships a documented behavior change along with it: claims must carry full paths where hierarchy matters, and the Group Membership mapper's help text now warns to enable full-path when your realm has duplicated group names. If you patch and walk away, this is the CVE most likely to leave your authorization semantics quietly different from what you configured — the same warning this site attached to the 26.7.4 policy-enforcer change.

Why the split? It is not an accident, and Keycloak's own security policy explains it: moderate findings may be fixed in the following minor. Two mediums landed by design in the next minor. The release notes just never turn that rule around and tell you what you are missing if you do not move.

What to actually do

  1. On 26.7.x at any level: upgrade to 26.8.0. Not 26.7.5 — 26.7.5 closes the brute-force family, the client-policy batch, the SAML pollution, and the secret-leak, and still leaves CVE-2026-12388 and CVE-2026-19608 open with no 26.7 fix available. Everything 26.7.5 has, 26.8.0 has (verified). Follow the upgrading guide; read the 26.8 behavior changes before you flatten, particularly around group-policy claims.
  2. Cannot move to 26.8.0 this week? Two temporary postures, in order of value: hold manage-identity-providers to full realm admins only (that permission is the entire gate on the 12388 escalation), and audit your existing IdP mappers for Hardcoded Role entries targeting administrative roles. For 19608, ensure group claims in your authorization configs carry full paths, and review any group policy that relies on path-specific matching in a realm with duplicate group names. Both are containment, not fixes.
  3. Already on 26.8.0: covered for all twenty identifiers. Your list is unchanged from the October 2 post — the config review, the opt-in secure-client-node-hostname executor, the multi-site deprecation clock.
  4. Red Hat Build of Keycloak: at publish time, the Bugzilla entries for this batch still show no fixed-in product versions. Match your stream against the RHBK errata before assuming coverage either way.
  5. Version-map discipline — the generalizable lesson: when a minor line ships its point release the day before the next minor, the two notes together are one release, and no document says so. Decide upgrades by diffing tags or reading both lists, never by one note. A version range in NVD is a hope, not data — for this batch there wasn't even a hope.

Closing

Twenty CVE identifiers shipped across two consecutive days, and the systems institutions trust to explain such things — advisory databases — contained no version information for any of them. The release notes each described only their own tag. Nothing here required speculation: the tags are public, the diffs are small enough to read, and every question this post answers could be answered by anyone in an afternoon. That is the auditability FOSS promises, and it was only accessible to someone willing to do the diff. Most operators are not. That gap — between "the sources exist" and "the sources explain anything" — is where community infrastructure keeps getting caught. Close it with one habit: when two releases land that close together on a stack you run, diff them before you decide either is enough.

Sources: Keycloak 26.7.5 release notes; Keycloak 26.8.0 release / release notes; Keycloak 26.8.0 tag; Bugzilla 2501736 / CVE-2026-16103; Bugzilla 2531302 / CVE-2026-88770; Bugzilla 2489140 / CVE-2026-12388; CVE-2026-19608 advisory; Keycloak Security Policy; upstream tag diffs 26.7.5...26.8.0 produced for this post (file-level comparisons in CibaGrantType.java, DeviceGrantType.java, BackchannelAuthenticationEndpoint.java, IdentityProviderResource.java, GroupPolicyProvider.java, SecureClientUrisExecutor.java, KeycloakUriBuilder.java, BaseSAML2BindingBuilder.java, AccessTokenIntrospectionProvider.java, AbstractClientRegistrationProvider.java, RoleResolveUtil.java, AudienceProtocolMapper.java, pom.xml).