SendTech Times
News
MARKET SIGNAL:

Rails Fixes Critical Active Storage File-Read Vulnerability

Newsroom brief

BleepingComputer reported that Rails maintainers patched CVE-2026-66066, a critical Active Storage flaw tied to libvips image processing and possible file exposure in vulnerable applications.

Verified against source materialEdited by SendTech Times Cybersecurity DeskSource: BleepingComputer
Rails Fixes Critical Active Storage File-Read Vulnerability
Image source: BleepingComputer

A critical Active Storage vulnerability has moved Rails security work from ordinary patching to credential containment, BleepingComputer reported, because vulnerable applications can expose server files when untrusted image uploads are processed with libvips.

The Rails advisory tracks the flaw as CVE-2026-66066 and gives it a critical severity rating.

Active Storage handles file uploads and attachments in Rails applications, so the affected surface sits inside a common web-application workflow rather than a separate optional security product.

Vulnerable Image Processing Is The Gate

The security bulletin says exploitation depends on libvips being used for image processing and on the application accepting image uploads from untrusted users.

In that configuration, a crafted image can let an unauthenticated attacker read arbitrary files from the server, with possible escalation to remote code execution.

The operational risk comes from what those files may contain.

Environment data and application files can include the Rails secretkeybase, database credentials, cloud storage credentials and other service secrets available to the application process.

A file-read bug can therefore become a broader credential rotation event for teams that exposed the vulnerable path.

Patched Rails Versions Narrow The Upgrade Path

The affected ranges span current Active Storage release lines, including the patched 8.0.x series and older maintained builds, according to the Rails advisory.

Exposure in Rails 6.x is narrower because it depends on a non-default Active Storage configuration.

According to the Rails security bulletin, deployments should upgrade to libvips 8.13 or later, and systems already on libvips 8.13 or later can use VIPSBLOCKUNTRUSTED or Vips.block_untrusted(true) as temporary controls when ruby-vips 2.2.1 or newer is in use.

Operators also need to replace the framework master key and review database, storage and service credentials that the running application could read, because the bug class is file exposure rather than only upload failure.

Default Stack Choices Matter

ImageMagick users are not affected by this vector, but libvips is the default processor in official Rails Docker images and in Debian and Ubuntu setups.

That default matters for teams that adopted standard deployment images without separately reviewing how upload processing touches server-side files.

The maintainers withheld full technical details to reduce exploitation risk while users patch.

The source record listed August 28 as the initial date for fuller disclosure on the Rails forums, leaving administrators with a short-term checklist: upgrade the affected components, identify untrusted upload paths and rotate secrets where vulnerable processing may have exposed application state.

Share this article
inXf

Related articles

More
UK Energy Cyberattack Shut Small Generator For Four Days
Cybersecurity

UK Energy Cyberattack Shut Small Generator For Four Days

A small U.K. energy generator was shut for four days after a July cyberattack linked to Iran, while officials said the wider power system was not at risk.

Metabase Zero-Day Forces Patch And Breach Checks
Cybersecurity

Metabase Zero-Day Forces Patch And Breach Checks

BleepingComputer reported active exploitation of a critical Metabase SQL injection zero-day affecting cloud and self-hosted deployments, with Framework and Tally disclosing customer data exposure.

IBM Buys Logiq to Deepen UK Cybersecurity Work in Regulated Sectors
Politics

IBM Buys Logiq to Deepen UK Cybersecurity Work in Regulated Sectors

IBM UK has acquired Logiq Consulting, adding NCSC-assured cybersecurity, Secure by Design and sovereign collaboration expertise for defence, critical infrastructure and public-sector clients.

PLDT Pitches Integrated Cloud, Security and Connectivity Strategy for Enterprise Clients
Telco & Connectivity

PLDT Pitches Integrated Cloud, Security and Connectivity Strategy for Enterprise Clients

PLDT is positioning connectivity, wireless, cloud, cybersecurity and digital services as one enterprise relationship as customers modernize around AI, resilience and procurement priorities.

Google Limits Gemini Cyber Defense Program To Trusted Partners
AI

Google Limits Gemini Cyber Defense Program To Trusted Partners

Google opened its Fairwind Program to approved governments, Google Cloud customers and security partners, pairing Gemini 3.8 Flash Cyber with CodeMender under controlled access rules.

DeadLock Ransomware Uses Polygon To Keep Victim Chats Reachable
Cybersecurity

DeadLock Ransomware Uses Polygon To Keep Victim Chats Reachable

BleepingComputer reported that DeadLock ransomware now uses Polygon smart-contract lookups to refresh victim chat infrastructure while spreading extortion services across Session and Wasabi.

CrowdStrike Sees AI Attacks Converging With SaaS And Cloud Identity Risk
Cybersecurity

CrowdStrike Sees AI Attacks Converging With SaaS And Cloud Identity Risk

Back End News framed CrowdStrike’s 2026 threat outlook around AI-enabled attacks, resilient ransomware and cloud identity exposure as enterprises expand AI and SaaS use.

DOJ Domain Seizures Target QTFY Botnet Alleged To Mask Chinese Hacking
Cybersecurity

DOJ Domain Seizures Target QTFY Botnet Alleged To Mask Chinese Hacking

The U.S. Justice Department seized three domains tied to QTFY, a group accused of using QScan and QTRouter malware to compromise IoT devices and disguise malicious traffic. The case links the infrastructure to critical-infrastructure intrusions dating to 2018 and a NASA-related FBI investigation in 2019.

Keep Reading

More Stories

Latest
Kepler Targets 2027 Production for HBM Replacement MemoryCloud & Data CentersOct 6, 2026Kepler Targets 2027 Production for HBM Replacement MemoryEE Times reports that Kepler Computing is preparing 3D ferroelectric memory for 2027 production, promising higher capacity and bandwidth per watt while limiting reliance on advanced-node lithography.Yokogawa Opens Singapore Hub For Industrial Cyber ResilienceCapital & PolicyOct 6, 2026Yokogawa Opens Singapore Hub For Industrial Cyber ResilienceYokogawa Engineering Asia has launched a Singapore center focused on OT cyber resilience, training, response planning and recovery coordination for Southeast Asia, Oceania and Taiwan.ClickFix Attack Uses Browser Cache To Hide Malware PayloadCybersecurityOct 6, 2026ClickFix Attack Uses Browser Cache To Hide Malware PayloadMicrosoft Threat Intelligence traced a ClickFix cache-smuggling method that preloads malware into browser caches, then uses file size checks and a pasted Run command to launch later credential-theft stages.VOA Tests Six-Month Startup Buildout Before Funding DecisionsFintech & Digital PaymentsOct 6, 2026VOA Tests Six-Month Startup Buildout Before Funding DecisionsTechCabal’s interview with VOA Venture Partners founder Victoria Olayide Adesanya describes a six-month build programme that lets the firm work inside African financial-infrastructure startups before deciding whether to invest.Bitcoin Holds $86,000 As Dollar Index Hits 18-Month HighCrypto/Web3Oct 6, 2026Bitcoin Holds $86,000 As Dollar Index Hits 18-Month HighCoinDesk reported that bitcoin stayed near $86,000 while the U.S. Dollar Index reached about 102.5, with U.S. rate expectations and European political risks strengthening the dollar backdrop.Google Freezes OSS Bug Bounty Reports After AI Submission FloodCybersecurityOct 6, 2026Google Freezes OSS Bug Bounty Reports After AI Submission FloodGoogle has stopped accepting new product vulnerability reports in its OSS VRP after invalid automated submissions swamped reviewers, while older reports and some Cloud VRP routes remain open.Fleuret AI Raises €4M For Continuous AI Pentesting PlatformCybersecurityOct 6, 2026Fleuret AI Raises €4M For Continuous AI Pentesting PlatformTech.eu reported that French startup Fleuret AI raised €4 million in pre-seed funding to develop an agentic-AI platform that turns penetration testing into a continuous security process.GFT Analysis Says AI Documentation Can Cut Maintenance Work 30%Fintech & Digital PaymentsOct 6, 2026GFT Analysis Says AI Documentation Can Cut Maintenance Work 30%A GFT Technologies analysis says AI-linked software documentation can cut maintenance effort and speed developer onboarding when knowledge assets stay synchronized with code changes.Schneider Electric Lines Up $22.6 Billion PTC DealAIOct 5, 2026Schneider Electric Lines Up $22.6 Billion PTC DealSchneider Electric plans to buy PTC in a cash transaction valuing the US engineering software provider’s equity at about $22.6 billion, adding product-lifecycle software to its industrial AI push.Aggarwal Pledges Ola Electric Stake To Fund ₹1,000 Cr Rights IssueCapital & PolicyOct 5, 2026Aggarwal Pledges Ola Electric Stake To Fund ₹1,000 Cr Rights IssueOla Electric founder Bhavish Aggarwal pledged 20 Cr shares to finance his participation in a rights issue that forms part of a larger ₹1,500 Cr fundraising plan.Natrona Schools AI Review Puts Student Privacy Ahead Of Classroom Tool UseAIOct 5, 2026Natrona Schools AI Review Puts Student Privacy Ahead Of Classroom Tool UseNatrona County trustees questioned whether teacher AI tools expose student data, even as existing district rules already ban unauthorized generative AI use by students.AMD Prices 256-Core EPYC 9996 At $14,904 For Server BuyersChips & SemiconductorsOct 5, 2026AMD Prices 256-Core EPYC 9996 At $14,904 For Server BuyersTechRadar reports that AMD’s 6th Gen EPYC 9006 “Venice” lineup includes a 256-core EPYC 9996 with 512 threads, 1GB of L3 cache, a 600W default power rating and a $14,904 list price for 1,000-unit orders.