Ruby on Rails patches critical CVSS 9.5 vulnerability...update recommended

TL;DR AI
2 min readKey summary
Ruby on Rails has patched CVE-2026-66066 in Active Storage.
The flaw could let unauthenticated attackers abuse image transformation features to read arbitrary files and environment variables.
Stolen secrets could lead to remote code execution and lateral movement across internal systems.
Users are advised to update the affected components and libvips, and rotate any exposed credentials.
