Security News

Cybersecurity news aggregator

CRITICAL Vulnerabilities SC Media

Critical vulnerability in Rails Active Storage could lead to RCE

  • What: A critical vulnerability in Ruby on Rails Active Storage allows RCE
  • Impact: Servers using affected versions are at risk of remote code execution and data exposure
Read Full Article →

Vulnerability Management Critical vulnerability in Rails Active Storage could lead to RCE August 3, 2026 Share By SC Staff Adobe Stock Per Bleeping Computer, a critical vulnerability identified as CVE-2026-66066 has been discovered in the Active Storage component of the Ruby on Rails web application framework. This flaw allows unauthenticated attackers to potentially read arbitrary files from a vulnerable server and escalate to remote code execution (RCE). The vulnerability specifically affects Active Storage versions prior to 7.2.3.2, 8.0.x before 8.0.5.1, and 8.1.x before 8.1.3.1, particularly when the libvips image processing library is in use. Attackers can exploit this by uploading a specially crafted image to a server that allows untrusted image uploads. Successful exploitation could grant access to sensitive application files, including the process environment which often contains critical credentials like the secret_key_base, database passwords, and cloud storage keys. Security firm Akamai has dubbed the attack chain "KindaRails2Shell," emphasizing that compromising the secret_key_base allows for session cookie forgery, global ID signing, and manipulation of serialized data, leading to full RCE. While ImageMagick users are unaffected, libvips is the default processor in official Rails Docker images and common Linux distributions. The Rails team recommends upgrading libvips to version 8.13 or later and rotating all sensitive credentials. Forensic investigation tools and detailed technical information have been released due to the rapid emergence of proof-of-concept exploits. Source: Bleeping Computer SC Staff Related Vulnerability Management Coldcard hardware wallet firmware flaw led to $70 million Bitcoin theft SC Staff August 3, 2026 The vulnerability, identified by Block and detailed by Galaxy Research, occurred because a deterministic software pseudorandom number generator (PRNG) was used instead of the intended hardware random number generator (RNG) for seed generation. Vulnerability Management Adobe fixes critical vulnerabilities in Campaign Classic and Bridge SC Staff August 3, 2026 The critical vulnerability in Adobe Campaign Classic, identified as CVE-2026-48449, stems from incorrect authorization and poses a significant risk for remote code execution. Vulnerability Management Why responsible vulnerability disclosure is now a boardroom issue Kara Sprague August 3, 2026 Organizations need a clear vulnerability disclosure process as AI speeds flaw discovery. Related Events Cybercast State of Vulnerability Management Thu Sep 10 Cybercast Why Mythos is the cybersecurity crisis we need On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Bug Buffer Overflow Disassembly You can skip this ad in 5 seconds

Share this article