KindaRails2Shell: arbitrary file read to RCE in Rails Active Storage via libvips (CVE-2026-66066)
Updated:
Executive Summary
[object Object]
Analysis
Originally published by r/netsec on Jul 30, 2026.
Related Threats
NatWest appoints LSEG's Triona O’Keeffe chief data and analytics officer
NatWest has recruited London Stock Exchange executive Triona O’Keeffe as its new chief data and analytics officer as part of a move to bring its data, AI and engineering capabilities closer together.
NVD CRITICAL: CVE-2026-66421 — OpenClaw Dashboard contains a stored cross-site scripting vulnerability that all...
OpenClaw Dashboard contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to execute arbitrary JavaScript in the administrator's browser session by injecting HTML markup into agent transcript messages processed through the sessions API. Attackers can craft a message containing inline event handler payloads such as an img tag with an onerror attribute with
NVD HIGH: CVE-2026-66420 — MeshCentral 1.1.21 contains a cross-site WebSocket hijacking protection bypass v...
MeshCentral 1.1.21 contains a cross-site WebSocket hijacking protection bypass vulnerability that allows unauthenticated remote attackers to hijack authenticated administrator sessions by exploiting an unconditional early return in the CheckWebServerOriginName() function within webserver.js when self-signed certificates are in use. Attackers can open cross-origin WebSocket connections to any of th