Rails CVE-2026-66066: Patch Isn't Enough
CVE-2026-66066 lets an unauthenticated upload read server files via Active Storage. Patching Rails is not enough - libvips must go to 8.13 and secrets rotate.
Browse through our blog page filled with updated information and the latest tips to help you achieve your goals.
