Government Rails Site Hit 8 Hours After CVE Patch

Government Rails Site Hit Hours After CVE Patch

Government Rails Site Hit 8 Hours After CVE Patch

Rietta, a firm managing Rails apps for HIPAA-covered entities and state agencies, patched a critical ActiveStorage RCE (CVE-2026-66066) within hours of disclosure, only to see an attack attempt against a state government client eight hours later. Public PoC code appeared before their patch was even complete, and sustained probing continued for a month. The incident reveals that coordinated disclosure timelines fail as patch diffs enable rapid exploit development, urging defenders to treat security releases as urgent regardless of CVSS scores.

The moment a patch ships, the fix itself, a public code diff, is available to anyone willing to read it instead of waiting for a plain-English writeup.
  1. throwatdem12311

    Just sent this to my boss. Felt like tossing a grenade over a fence into a party of unsuspecting people.

    We don’t use ActiveStorage but Claude was able create a similar exploit in own our app in the exact same way via our own file upload library in 3 minutes simply by point Opus 5 at our site and asking it if we were vulnerable to an attack similar to KindaRails2Shell.

    What a time to be alive.

  2. tyre

    This post could be 10% as long:

    - There was a bug with a patch

    - We applied it to our clients

    - There were live exploits within eight hours of the patch being released

    - The Rails team had to expedite release of the technical details because POCs obviated the need to embargo

  3. comrade1234

    Do you have to have matlab running on your rails server for this to happen?

  4. jeremyjh

    Nice write up, Claude.

  5. onemoresoop

    This website is format is really weird for mobile, I can only read two lines of text. The rest is covered by a big banner. Im on IOS. Anybody else having this issue or is it just me?

More from this day

2026-09-04