CRITICAL: Ruby on Rails CVE-2026-66066 Exploited in the Wild
Attackers are actively exploiting CVE-2026-66066, the CVSS 9.5 Active Storage flaw in Ruby on Rails nicknamed KindaRails2Shell, with VulnCheck detections jumping from 50 to 360 in under two days. A crafted image upload gives an unauthenticated attacker arbitrary file read and a path to remote code execution. Patched in Active Storage 7.2.3.2, 8.0.5.1, and 8.1.3.1, and the fix also requires libvips 8.13 or newer.