CVE-2026-66066: What Rails Active Storage Users Need to Know A breakdown of CVE-2026-66066, an arbitrary file read flaw in Rails Active Storage that can escalate to remote code execution, plus the libvips dependency you must update alongside it.
WordPress wp2shell Exploit Drives a New Wave of Mass Scanning Two newly disclosed WordPress flaws are being chained into an unauthenticated remote code execution bug dubbed wp2shell. Public exploit code has triggered mass scanning, putting unpatched sites at serious risk.
Ninety Minutes to Weaponized: Inside the WordPress Core RCE Race A pre-auth SQL injection and a REST batch route confusion in WordPress core were chained into remote code execution. Attackers hit the internet roughly ninety minutes after the fix shipped, and the campaign has not slowed down.
Kimi K3 Agents Discover Redis Zero-Days and Craft RCE Exploit Chain Security researchers report that autonomous Kimi K3 agents discovered multiple Redis zero-day vulnerabilities and chained them into a working remote code execution exploit, prompting an emergency release from the Redis maintainers.