Herodevs Critical RCE Vulnerability in Rails Active Storage Disclosed
Article Content
- •CVE-2026-66066 is a critical RCE vulnerability affecting Rails Active Storage.
- •The flaw allows unauthenticated attackers to read arbitrary files on the server.
- •Patches are available in specific Rails versions; users must upgrade to secure their applications.
On July 29, 2026, the Ruby on Rails security team published CVE-2026-66066, a critical arbitrary file read and remote code execution (RCE) vulnerability in Active Storage. Discovered by the Ethiack research team, this flaw affects default configurations of Rails 6.x, 7.x, and 8.x that utilize the vips image processor. Attackers can exploit this vulnerability to read arbitrary files on the server, including sensitive credentials, without authentication in certain setups. The vulnerability has been assigned a CVSS score of 9.5 and affects an estimated 500,000+ sites. Fixes were released in Rails versions 7.2.3.2, 8.0.5.1, and 8.1.3.1. Users are advised to upgrade immediately to mitigate the risk. The vulnerability is particularly concerning due to the widespread use of Active Storage in production applications.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (16)
Following this threat?
Track Debian and CVE-2026-64645 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Exploitation of Ruby on Rails Vulnerability CVE-2026-66066 Confirmed Threat actors are actively exploiting CVE-2026-66066, a critical Ruby on Rails vulnerability known as KindaRails2Shell, which allows unauthenticated attackers to read arbitrary files from servers, potentially leading to remote code execution (RCE). Disclosed on July 30, 2026, this flaw affects numerous applications…
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…