August 4, 2026
- Rapid7 dropped a technical teardown of the Rails Active Storage RCE (CVE-2026-66066). "KindaRails2Shell" allows unauthenticated file reads and potential RCE via image processing; the analysis details the exploitation path (Rapid7). Builds on earlier coverage. · Vulnerabilities & Exploits
in Attackers Seize N-central RMM Servers After N-able's Second Fix Falls Short