A critical vulnerability in Ruby on Rails, tracked as CVE-2026-66066 and rated with a CVSS score of 9.5, is being exploited for remote code execution (RCE). This flaw allows unauthorized access to server files by leveraging improper handling of file types in image processing, particularly with the libvips library. Exploit attempts began shortly after the vulnerability was publicly disclosed in late July 2026, despite patches being issued.
Researchers have noted that even patched systems may remain susceptible under certain conditions. Approximately 7,000 instances were identified as vulnerable shortly after the exploitation began.