VulnCheck reported active exploitation of two critical flaws, one in the AI workflow builder Langflow and one in Ruby on Rails. The Langflow bug, CVE-2026-0768, scored 9.8, lets an attacker run arbitrary Python code as root through improper input validation. The Rails bug, CVE-2026-66066 and nicknamed KindaRails2Shell at 9.5, lets an unauthenticated attacker read arbitrary files by uploading a crafted image that exploits a mismatch between Active Storage and the libvips image library, leaking secrets like the Rails master key and cloud credentials and ultimately enabling code execution. Detections jumped from about 50 to 360 within a day, with attackers querying environment variables for OpenAI and AWS keys and probing SSH access.
The Ruby on Rails team disclosed a critical flaw in Active Storage that lets an unauthenticated attacker read arbitrary files by uploading a crafted image. Tracked as CVE-2026-66066 and scored 9.5, it affects applications that use the libvips image library and accept image uploads from untrusted users, which is the default in modern Rails. Active Storage passes uploads to libvips without disabling its unsafe image loaders, so a malicious file can read the server process environment, exposing the secret key base, database passwords, cloud storage keys, and API tokens. Those secrets can enable code execution and lateral movement. Rails is not aware of exploitation, and full details are held until August 28.