CVE-2026-66066

exploited in the wild☆ pin
CVSS
9.5
Reports
4
First seen
Jul 29, 2026
Last seen
Aug 3, 2026
Affected product

Ruby on Rails Active Storage (libvips backend) Rails 6.0.0–6.1.7.10, 7.0.0–7.2.3.1, 8.0.0–8.0.5, 8.1.0–8.1.3

Associated actors

Recent reports

This page shows data on a 7-day delay. Free accounts get the full delayed feed; real-time reports, indicators, and the API start at $29/mo.