Critical Ruby on Rails Vulnerability in Attackers’ Crosshairs
Reported exploitedRuby on RailsOur summary
VulnCheck has reported active exploitation of CVE-2026-66066, a critical remote code execution vulnerability in Ruby on Rails affecting applications that use libvips for image processing in Active Storage. Dubbed "KindaRails2Shell," this flaw allows unauthenticated attackers to read arbitrary files and potentially execute code by abusing discrepancies between how different libraries interpret file types. Although patches were released in late July, the vector remains severe with a CVSS score of 9.5, and approximately 7,000 exposed instances were identified earlier this month.
SecurityWeek publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.