Keycloak 26.7.1 (security update)
The release 26.7.1 of Keycloak is available on Clever Cloud. It includes the new capabilities introduced in Keycloak 26.7.0, such as the SCIM API promoted to preview, simplified multi-cluster high availability without external caches, step-up authentication for SAML clients and the experimental Admin API v2 for declarative client management.
This security update addresses twelve vulnerabilities: CVE-2026-9793, CVE-2026-4629, CVE-2026-14209, CVE-2026-14614, CVE-2026-14615, CVE-2026-15573, CVE-2026-15572, CVE-2026-16100, CVE-2026-16442, CVE-2026-16443, CVE-2026-16071 and CVE-2026-16102.
You can update through the add-on’s dashboard in the Clever Cloud Console. You can also set CC_KEYCLOAK_VERSION of the underlying Java application to 26.7.1 and rebuild it, or use Clever Tools:
clever features enable operators
clever keycloak version check yourKeycloakNameOrId
clever keycloak version update yourKeycloakNameOrId
clever keycloak version update yourKeycloakNameOrId 26.7.1
