Rails CVE-2026-66066: Patch Isn't Enough
CVE-2026-66066 lets an unauthenticated upload read server files via Active Storage. Patching Rails is not enough - libvips must go to 8.13 and secrets rotate.
Founder-tested patterns from 17 years of rescue engagements. Rails, AI, and the questions burned founders ask before signing again.









