View Ridge Security
Back to Cyber HoseVendor Bulletins & Advisories

Rails patches critical Active Storage flaw with remote code execution

๐Ÿ“‹ ADVISORIES

  • Rails patches critical Active Storage flaw with remote code execution risk
    Rails patched a critical Active Storage vulnerability allowing unauthenticated file read and remote code execution.
    • Affects Rails Active Storage versions before 7.2.3.2, 8.0.x before 8.0.5.1, and 8.1.x before 8.1.3.1
    • Vulnerability exploitable when libvips image processor is used and untrusted image uploads are allowed
    • Attack enables reading arbitrary files including secret_key_base and credentials, leading to remote code execution
    • Discovered by Ethiack and GMO Flatt Security, with Akamai naming the attack chain 'KindaRails2Shell'
    • Full technical details and forensic tools released after public proof-of-concept exploits appeared
      ๐Ÿ“Ž Coverage: bleepingcomputer.com ยท ๐Ÿ“„ Original: bleepingcomputer.com ยท ๐Ÿ‘ via BleepingComputer

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • Scope of Cyberattacks on U.S. Water Supply Expands, Linked to Iran
    Cyberattacks on U.S. water supply systems have expanded with evidence pointing to Iran.

    • Targets: U.S. water supply infrastructure
    • Impact: Expansion of hacking incidents affecting water systems
    • Attribution: Evidence suggests involvement of Iranian actors
    • Attack details: Specific CVEs not disclosed; methods not detailed in source
      ๐Ÿ“Ž Coverage: infosec.exchange ยท ๐Ÿ‘ via @metacurity@infosec.exchange
  • Multiple high-severity vulnerabilities found in FreeRDP before version 3.29.0 CVE-2026-67288 CVE-2026-67291 CVE-2026-67292 CVE-2026-67295 CVE-2026-67298 CVE-2026-67299 CVE-2026-67300 CVE-2026-67303
    FreeRDP versions before 3.29.0 contain multiple critical vulnerabilities including heap overflows and use-after-free bugs.

    • Applies to FreeRDP versions 3.28.0 and earlier, fixed in 3.29.0
    • Includes heap buffer overflow via RAIL orderLength underflow allowing server crashes
    • Heap out-of-bounds read in glyph cache processing can cause client crashes
    • Client-side use-after-free vulnerabilities in async message proxies lead to memory corruption
    • Denial of service via null pointer dereference in smartcard cache and assertion failure in serial device control
    • Path traversal in drive redirection and buffer over-disclosure in WebSocket transport also present
      ๐Ÿ“Ž Coverage: cve.threatint.com ยท ๐Ÿ“„ Original: cve.threatint.com ยท ๐Ÿ‘ via CVE ThreatInt (+7)
  • ArcadeDB before 26.7.2 vulnerable to remote code execution via trigger scripts CVE-2026-67340
    ArcadeDB versions before 26.7.2 allow remote code execution through malicious trigger scripts.

    • Applies to ArcadeDB versions before 26.7.2 (arcadedb-engine)
    • Vulnerability allows authenticated users with UPDATE_SCHEMA permission to execute OS commands
    • Trigger scripts can access java.lang.Runtime to invoke exec() or ProcessBuilder for code execution
    • Attack requires creation of a JavaScript trigger that fires and executes malicious commands
      ๐Ÿ“Ž Coverage: cve.threatint.com ยท ๐Ÿ“„ Original: cve.threatint.com ยท ๐Ÿ‘ via CVE ThreatInt
  • No Title
    Lost amid the news cycles on OpenAI's disclosure about poorly contained AI models that went on to hack into HuggingFace and other companies was this disclosure from the German health insurer Universa, which said OpenAI scraped customer data while it was supposedly unprotected due to a misconfigurati
    ๐Ÿ“Ž Coverage: infosec.exchange ยท ๐Ÿ‘ via @briankrebs@infosec.exchange

๐Ÿ”“ CVEs & KEV

  • CVE-2026-67324 โ€” CVSS 9.8 โ€” GitPython 3.1.50 Authentication Bypass via Joined Short Options
  • CVE-2026-67336 โ€” CVSS 8.7 โ€” better-auth before 1.6.11 Insecure Cryptographic Defaults via oidcProvider
  • CVE-2026-67333 โ€” CVSS 7.2 โ€” better-auth before 1.6.13 Stored XSS via javascript redirect_uri
  • CVE-2026-67326 โ€” CVSS 7.0 โ€” GitPython before 3.1.50 Newline Injection via config_writer section
  • CVE-2026-67311 โ€” CVSS 6.8 โ€” Budibase before 3.38.1 SSRF Blacklist Bypass via HTTP Redirect
  • CVE-2026-67354 โ€” CVSS 5.9 โ€” guzzlehttp/guzzle before 7.15.1 URI Fragment Disclosure via Referer
  • CVE-2026-67344 โ€” CVSS 4.3 โ€” ArcadeDB before 26.7.2 Authentication Bypass via ALTER TYPE
  • CVE-2026-67309 โ€” Traefik v3.7.0 Path Traversal via RewriteTarget Authentication Bypass
  • CVE-2026-67321 โ€” axios before 0.33.0 Denial of Service via maxDepth bypass
  • CVE-2026-67319 โ€” axios before 0.33.0 Prototype Pollution via nested option objects
  • CVE-2026-67329 โ€” @better-auth/stripe before 1.6.21 Authorization Bypass via Organization Subscription

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check