Critical Remote Code Execution Vulnerability in Ruby on Rails Active Storage (CVE‑2026‑66066) – Advisory and Mitigation
JPCERT‑AT issued an advisory for CVE‑2026‑66066, a remote‑code‑execution flaw in Ruby on Rails Active Storage when using libvips. The advisory details affected versions, exploitation conditions, available mitigations, and forensic detection steps.