CVE-2026-66066 breaks Rails Active Storage — one upload is all it takes to steal your master key and get RCE
On August 1, 2026, the Rails team patched CVE-2026-66066, a critical Active Storage vulnerability that allows unauthenticated arbitrary file read and RCE escalation via libvips. Akamai named the chain 'KindaRails2Shell' and confirmed full remote-code-execution potential.