• Sources: primary, discussion
  • Summary: The post describes CVE-2026-66066 as a remote code execution flaw in ActiveStorage affecting Ruby on Rails 8 and newer, fixed in the Rails security release of 2026-07-29. The ActiveStorage advisory withheld attack detail until 2026-08-28 while the fix diff was public from the first hour, and a public proof of concept appeared before the consultancy's patch landed. The post is a consultancy's account of its own client logs and closes with business development. The CVE, advisory, and proof-of-concept dates are checkable, and the attack log timestamps are not independently verifiable.
  • Why it matters: The recorded gap between patch publication and a working exploit attempt was hours rather than the weeks an embargo on attack detail implies.

send feedback on this story