Government Rails Site Hit 8 Hours After CVE Patch

Government Rails Site Hit Hours After CVE Patch

Government Rails Site Hit 8 Hours After CVE Patch

Rietta, a firm managing Rails apps for HIPAA-covered entities and state agencies, patched a critical ActiveStorage RCE (CVE-2026-66066) within hours of disclosure, only to see an attack attempt against a state government client eight hours later. Public PoC code appeared before their patch was even complete, and sustained probing continued for a month. The incident reveals that coordinated disclosure timelines fail as patch diffs enable rapid exploit development, urging defenders to treat security releases as urgent regardless of CVSS scores.

The moment a patch ships, the fix itself, a public code diff, is available to anyone willing to read it instead of waiting for a plain-English writeup.

More from this day

2026-09-04