THREATOPS
THREAT OPSThreat News › KindaRails2Shell: CVE-2026-66066, Critical Arbitrary File Read and Possible Remote Code Execution in Ruby on Rails

KindaRails2Shell: CVE-2026-66066, Critical Arbitrary File Read and Possible Remote Code Execution in Ruby on Rails

medrapid7Published 2026-07-30

<h2 style="direction: ltr;">Overview</h2><p style="direction: ltr;"><span style="font-size: undefined;">On July 29, 2026, the Ruby on Rails project </span><a href="https://github.com/rails/rails/security/advisories/GHSA-xr9x-r78c-5hrm"><span style="font-size: undefined;">published a security advisory</span></a><span style="font-size: undefined;"> for </span><a href="https://www.cve.org/CVERecord?i

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://www.rapid7.com/blog/post/etr-kindarails2shell-cve-2026-66066-critical-arbitrary-file-read-and-possible-remote-code-execution-in-ruby-on-rails

Same event, other sources