AI & Enterprise
Ruby on Rails patches critical CVSS 9.5 flaw, urges update
Ruby-based web development framework Ruby on Rails has released a patch for a serious vulnerability that could allow unauthenticated attackers to execute remote code, SecurityWeek reported. The flaw, tracked as CVE-2026-66066 and rated 9.5 on the CVSS scale, involves arbitrary file reads that could expose secrets and enable lateral movement. Administrators urged users to update affected Active Storage versions and raise libvips to at least 8.13.