Skip to content
ArxDecoded

ArxDecoded

  • Home
  • AI & Emerging
  • Dev & Open Source
  • Cloud & Security
  • Hardware & Chips
  • Mobile & Web

security advisory

Critical Remote Code Execution Vulnerability in Ruby on Rails Active Storage (CVE‑2026‑66066) – Advisory and Mitigation

August 25, 2026

JPCERT‑AT issued an advisory for CVE‑2026‑66066, a remote‑code‑execution flaw in Ruby on Rails Active Storage when using libvips. The advisory details affected versions, exploitation conditions, available mitigations, and forensic detection steps.

Categories Cybersecurity

Metabase SQL Injection Vulnerability (CVE‑2026‑72898): Impact, Affected Versions, and Mitigation

August 25, 2026

JPCERT‑AT warns that Metabase versions prior to specific releases contain an unauthenticated SQL injection (CVE‑2026‑72898) that can grant admin access. Learn which versions are affected, how attackers exploit it, and what immediate steps you should take.

Categories Cybersecurity
  • About
  • Sources
  • Contact
  • Disclaimer
  • Privacy Policy
  • Sitemap
© 2026 ArxDecoded · Clear technology, grounded in evidence.