www.securityweek.com 8/31/2026, 11:29:27 AM · external

CVE-2026-66066 Ruby on Rails Flaw Triggers Remote Code Execution

CVE-2026-66066 Ruby on Rails Flaw Triggers Remote Code Execution
CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Status Unknown

A critical vulnerability in Ruby on Rails, tracked as CVE-2026-66066 and rated with a CVSS score of 9.5, is being exploited for remote code execution (RCE). This flaw allows unauthorized access to server files by leveraging improper handling of file types in image processing, particularly with the libvips library. Exploit attempts began shortly after the vulnerability was publicly disclosed in late July 2026, despite patches being issued.

Researchers have noted that even patched systems may remain susceptible under certain conditions. Approximately 7,000 instances were identified as vulnerable shortly after the exploitation began.

View Primary Source Via www.securityweek.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline