CVE-2026-66066
exploited in the wild☆ pinCVSS
9.5
Reports
4
First seen
Jul 29, 2026
Last seen
Aug 3, 2026
Affected product
Ruby on Rails Active Storage (libvips backend) Rails 6.0.0–6.1.7.10, 7.0.0–7.2.3.1, 8.0.0–8.0.5, 8.1.0–8.1.3
Associated actors
Recent reports
Critical