JetThoughts has been building software since 2008. Book a call, or write to sales@jetthoughts.com. You'll leave the call with a written one-page scope within 2 working days.

A 30-minute call; pick a time.

CVE-2026-66066 lets an unauthenticated upload read server files via Active Storage. Patching Rails is not enough - libvips must go to 8.13 and secrets rotate.
· JetThoughts
Rails 7.1 got no patch for CVE-2026-66066, a CVSSv4 9.5 pre-auth RCE. How to find every app of yours on a dead branch and pick between four realistic exits.
· JetThoughts
CVSS 8.1 universal RCE chain through ERB::DeprecatedInstanceVariableProxy and Marshal.load. Detection, upgrade path, Rails 7.0/7.1 EOL options.
· JetThoughtsJetThoughts has been building software since 2008. Book a call, or write to sales@jetthoughts.com. You'll leave the call with a written one-page scope within 2 working days.

A 30-minute call; pick a time.