Ruby on Rails has patched CVE-2026-66066, a critical vulnerability leading to unauthenticated file reads and potentially RCE.

A critical Active Storage vulnerability allows arbitrary file read and possible remote code execution through libvips variant processing. Here's what to check and how to patch.

CVE-2026-66066 could expose Rails server files through image uploads, leaking secrets that may enable RCE or lateral movement.