Government Rails Site Hit 8 Hours After CVE Patch
Government Rails Site Hit Hours After CVE Patch

Rietta, a firm managing Rails apps for HIPAA-covered entities and state agencies, patched a critical ActiveStorage RCE (CVE-2026-66066) within hours of disclosure, only to see an attack attempt against a state government client eight hours later. Public PoC code appeared before their patch was even complete, and sustained probing continued for a month. The incident reveals that coordinated disclosure timelines fail as patch diffs enable rapid exploit development, urging defenders to treat security releases as urgent regardless of CVSS scores.
The moment a patch ships, the fix itself, a public code diff, is available to anyone willing to read it instead of waiting for a plain-English writeup.
- throwatdem12311
Just sent this to my boss. Felt like tossing a grenade over a fence into a party of unsuspecting people.
We don’t use ActiveStorage but Claude was able create a similar exploit in own our app in the exact same way via our own file upload library in 3 minutes simply by point Opus 5 at our site and asking it if we were vulnerable to an attack similar to KindaRails2Shell.
What a time to be alive.
- tyre
This post could be 10% as long:
- There was a bug with a patch
- We applied it to our clients
- There were live exploits within eight hours of the patch being released
- The Rails team had to expedite release of the technical details because POCs obviated the need to embargo
- comrade1234
Do you have to have matlab running on your rails server for this to happen?
- jeremyjh
Nice write up, Claude.
- onemoresoop
This website is format is really weird for mobile, I can only read two lines of text. The rest is covered by a big banner. Im on IOS. Anybody else having this issue or is it just me?