Keycloak 26.7.3 Released: 20 CVEs, none an emergency
Bottom line: no emergency window, but upgrade this week if you use external token exchange with Google or Microsoft, or fine-grained admin permissions (FGAP) v2 with delegated admins. Keycloak 26.7.3 fixes 20 CVEs. The only high one is in a test-scope dependency and does not reach a running server — our reading, evidence below. Everything that does is medium or lower and needs a privileged account or an opt-in feature. The three breaking changes will bite you before any CVE does. If you run 26.4, 26.5 or 26.6, no tag carrying these fixes exists yet.