THREATOPS
THREAT OPSThreat News › Re: Rails CVE-2026-66066: Possible arbitrary file read and remote code execution in Active Storage variant processing

Re: Rails CVE-2026-66066: Possible arbitrary file read and remote code execution in Active Storage variant processing

medoss_secPublished 2026-08-01

<p>Posted by Alan Coopersmith on Jul 31</p>[...]<br /> <br /> That further disclosure has happened now, announced at:<br /> <a href="https://discuss.rubyonrails.org/t/cve-2026-66066-attack-details-and-tools-to-perform-a-forensic-investigation/91441" rel="nofollow">https://discuss.rubyonrails.org/t/cve-2026-66066-attack-details-and-tools-to-perform-a-forensic-investigation/91441</a><br />

Indicators of compromise

Original source: https://seclists.org/oss-sec/2026/q3/377

Same event, other sources