Critical Ruby on Rails Vulnerability Exploited in the Wild

Critical Ruby on Rails Vulnerability Exploited in the Wild

First seen 31 Aug 2026, 19:59 UTC Feeds.FeedburnerSecurityweekdocs.vulncheck.comgithub.com 75.0

Article Content

Browse articles
ThreatCluster

A critical-severity vulnerability in Ruby on Rails, tracked as CVE-2026-66066 and dubbed KindaRails2Shell, is being actively exploited by hackers, leading to remote code execution (RCE). Disclosed on July 30, 2026, this flaw allows unauthenticated attackers to read arbitrary files and potentially access sensitive data. The vulnerability affects Rails applications relying on libvips for image processing, particularly those accepting untrusted user uploads. Security researchers have identified around 7,000 vulnerable instances, and exploitation began shortly after the public release of proof-of-concept code. Despite patches released by Ruby on Rails, some exploitation vectors remain viable, as confirmed by VulnCheck's testing. The situation is urgent, with CISA listing this CVE in its KEV catalog due to active exploitation. Rails has also provided forensic tools to help detect attempts at exploitation.

Key Points: • CVE-2026-66066 allows remote code execution via arbitrary file reads. • Approximately 7,000 Ruby on Rails instances are currently vulnerable. • Exploitation began shortly after the release of proof-of-concept code.

Timeline

2026-07-23
CVE-2026-15981 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-30
CVE-2026-66066 published
Ruby on Rails disclosed a critical vulnerability leading to remote code execution.
Securityweek
2026-07-30
First public PoC released
Security researchers released proof-of-concept code targeting CVE-2026-66066.
Securityweek
2026-08-26
CVE-2026-8452 added to CISA KEV
CISA listed CVE-2026-8452 for active exploitation, indicating a growing threat landscape.
Securityweek
2026-08-27
CVE-2026-53362 added to CISA KEV
CISA added CVE-2026-53362 to its KEV catalog, confirming active exploitation.
Securityweek
2026-08-28
CVE-2026-82078 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-28
CVE-2026-81578 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-31
CVE-2026-66066 exploitation confirmed
VulnCheck reported that threat actors began exploiting the vulnerability last week.
Securityweek