Rietta deploys emergency patch for Rails ActiveStorage flaw CVE-2026-66066 same day it surfaced
Security firm Rietta rolled out an emergency hotfix across its client base on July 29, 2026, after a Ruby on Rails ActiveStorage vulnerability—later named KindaRails2Shell and tracked as CVE-2026-66066—jumped from an unrated update to a 9.5/10 CVSS severity score within hours. The flaw, discovered by researchers at Ethiack, allows arbitrary file read and remote code execution through variant processing in Active Storage, a core Rails component used in Rails 8 and newer.