Securityweek
Critical Ruby on Rails Vulnerability Exploited in the Wild
Article Content
A critical-severity vulnerability in Ruby on Rails, tracked as CVE-2026-66066 and dubbed KindaRails2Shell, is being actively exploited by hackers, leading to remote code execution (RCE). Disclosed on July 30, 2026, this flaw allows unauthenticated attackers to read arbitrary files and potentially access sensitive data. The vulnerability affects Rails applications relying on libvips for image processing, particularly those accepting untrusted user uploads. Security researchers have identified around 7,000 vulnerable instances, and exploitation began shortly after the public release of proof-of-concept code. Despite patches released by Ruby on Rails, some exploitation vectors remain viable, as confirmed by VulnCheck's testing. The situation is urgent, with CISA listing this CVE in its KEV catalog due to active exploitation. Rails has also provided forensic tools to help detect attempts at exploitation.
Key Points: • CVE-2026-66066 allows remote code execution via arbitrary file reads. • Approximately 7,000 Ruby on Rails instances are currently vulnerable. • Exploitation began shortly after the release of proof-of-concept code.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.