Rails has released security updates for a critical Active Storage vulnerability that can let unauthenticated attackers read arbitrary files from vulnerable web applications. The Rails Active Storage flaw, tracked as CVE-2026-66066, can also create a path to remote code execution. Attackers may steal application secrets first and then use them to take control of the…