Critical
CVE-2026-66066
Rails CVE-2026-66066 arbitrary file read and RCE with PoC release
Vendor / product: Rails Active Storage
Event date: 2026-07-29
Public PoC: Yes
First tracked by RiskWire: 2026-07-28
Sources & citations (19)
- Re: Rails CVE-2026-66066: Possible arbitrary file read and remote code execution in Active Storage variant processing seclists.org · 2026-08-01
- Patch Your Rails: Active Storage CVE-2026-66066 dev.to · 2026-07-29
- CVE-2026-66066: Defending Against the 'KindaRails2Shell' Pre-Auth RCE akamai.com · 2026-07-30
- KindaRails2Shell threatens Ruby on Rails apps (CVE-2026-66066) helpnetsecurity.com · 2026-08-03
- Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads thehackernews.com · 2026-07-29
- Critical Rails Flaw Lets Unauthenticated Attackers Read Server Files and Execute Code gbhackers.com · 2026-07-30
- Critical Rails Flaw Lets Attackers Read Arbitrary Files and Execute Malicious Code Remotely cybersecuritynews.com · 2026-07-30
- Rails CVE-2026-66066: Possible arbitrary file read and remote code execution in Active Storage variant processing seclists.org · 2026-07-29
- KindaRails2Shell (CVE-2026-66066): Arbitrary File Read and RCE via Active Storage Uploads dev.to · 2026-07-31
- Rails patches critical Active Storage flaw with RCE potential bleepingcomputer.com · 2026-08-01
- Rails CVE-2026-66066: Patch and Rotate Secrets blog.gridinsoft.com · 2026-08-02
- Ethiack Helps Remediate Critical Vulnerability That Exposed More Than 500,000 Websites cybersecurity-insiders.com · 2026-08-02
- Public PoC Released for Critical Rails Active Storage RCE Vulnerability cybersecuritynews.com · 2026-08-03
- What is CVE-2026-66066? Protecting Your Rails App from Active Storage RCE fastly.com · 2026-08-03
- Metasploit Exploit Targets Critical Ruby on Rails Active Storage RCE Flaw gbhackers.com · 2026-08-03
- Ruby on Rails Patches Critical Active Storage Vulnerability Affecting Image Processing securityaffairs.com · 2026-08-03
- Key theft in Ruby on Rails – Critical vulnerability with prepared images de.headtopics.com · 2026-08-03
- Ruby on Rails critical bug puts every image upload under scrutiny infoworld.com · 2026-08-05
- Ruby on RailsのActive Storageにおけるリモートコード実行につながる脆弱性(CVE-2026-66066)に関する注意喚起 jpcert.or.jp · 2026-07-30
References
See CVE-2026-66066 in context
RiskWire tracks every exploited CVE this week, cross-referenced against CISA KEV with federal remediation deadlines. Filtered to your vendor stack.
Book a 20-min demo →