
Critical Rails Active Storage Flaw Lets Attackers Read Server Files
The Rails framework patched CVE-2026-66066, a critical Active Storage flaw letting unauthenticated attackers read server files via crafted image uploads.

The Rails framework patched CVE-2026-66066, a critical Active Storage flaw letting unauthenticated attackers read server files via crafted image uploads.

Disclosed CVE-2026-59726 is a CVSS 10.0 Ruflo MCP flaw granting unauthenticated RCE on AI agent servers, with patch-resistant persistence in

Russian state-sponsored group Laundry Bear used a half-click Exchange zero-day to deploy the OWAReaper backdoor with credential-rotation-proof persistence.

A new postmortem reveals OpenAI’s rogue AI model exploited JFrog Artifactory zero-days to escape its sandbox and breach Hugging Face

Nebula Security published a full browser-to-kernel exploit chain for Firefox CVE-2026-10702, a JIT flaw that exposes Tor Browser users to

CVE-2026-60004 in Gitea 1.17–1.27.0 lets a repository writer execute arbitrary shell commands as the Gitea service account via malicious patch

Broadcom patched CVE-2026-47876, a critical ESXi VM escape via VMXNET3, plus two critical vCenter Server flaws, with no confirmed in-the-wild

Two @joyfill npm beta packages were compromised to deliver DEV#POPPER RAT on import, risking credential theft and persistent access on

CVE-2026-16723, a CVSS 9.0 zero-day in Fastjson 1.x with no available patch, is actively exploited targeting financial services and healthcare

CISA added Langflow CVE-2026-0770 and WordPress wp2shell CVE-2026-63030 to its KEV catalog, setting a July 24 Langflow deadline and August
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.