Rails security advisory (AV26-767)
Serial Number: AV26-767 Date: July 31, 2026 As of July 30, 2026, Rails is affected by a vulnerability in the following product: Rails Prior to 8.0.5.1 Prior to 8.1.3.1 Prior to 7.2.3.2 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Release 7.2.3.2 · rails/rails - GitHub Release 8.0.5.1 · rails/rails - GitHub Release 8.1.3.1 · rails/rails - GitHub [CVE-2026-66066] Possible arbitrary file read and remote code execution in Active Storage variant processing Release list - rails/rails
Details
Original advisory: https://cyber.gc.ca/en/alerts-advisories/rails-security-advisory-av26-767
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Moderate exploitation riskCVE-2026-660661.7% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 75% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-66066 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] Ruby on Rails: Vulnerability allows information disclosurecert-bund
- unknownCVE-2026-66066: Action Pack is a framework for handling and responding to web requests. In versions prior to 7…nvd
- criticalGHSA-xr9x-r78c-5hrm: Active Storage has possible arbitrary file read and remote code execution in Active Stora…ghsa
- unknownVulnerability in Ruby on Rails activestorage (July 30, 2026)cert-fr-avis
More from Canadian Centre for Cyber Security
- unknownGoogle security advisory (AV26-768)2026-07-31
- unknownSolarWinds security advisory (AV26-766)2026-07-31
- unknownGladinet security advisory (AV26-765)2026-07-30
- unknownPHP Group security advisory (AV26-764)2026-07-30
- unknownVMware security advisory (AV26-763)2026-07-30