
Public PoC Released for Critical Rails Active Storage RCE Vulnerability
A critical vulnerability in Ruby on Rails has raised new concerns about cloud data breaches, particularly for companies that host customer platforms in Amazon Web Services (AWS). Known as CVE-2026-66066 or KindaRails2Shell, this flaw affects Active Storage deployments that utilize the libvips image-processing library and accept uploads from untrusted users. While there is no specific […]
The post Public PoC Released for Critical Rails Active Storage RCE Vulnerability appeared first on Cyber Security News.