
Ruby on Rails has released security updates for a critical Active Storage vulnerability that can allow an unauthenticated attacker to read arbitrary files from an application server through crafted image uploads. Tracked as CVE-2026-66066 and rated 9.5 on the CVSS scale, the flaw can expose secrets accessible to the Rails process and potentially enable remote […]
The post CVE-2026-66066: Critical Rails Flaw Exposes Server Files via Image Uploads appeared first on SOC Prime.