All Systems Operational
About This Site
Here we will post updates about Inline Manual's service availability.
Past Incidents
Aug 6, 2026
No incidents reported today.
Aug 5, 2026
Resolved -
Resolved - no evidence of exploitation
We have completed our investigation into the potential impact of CVE-2026-66066.
We took a deliberately thorough approach and went beyond our standard review process to ensure we had examined every relevant source of information. This included:
- Patching the affected systems immediately
- Reviewing application, infrastructure, and access logs covering the relevant period
- Searching for known indicators and patterns associated with exploitation
- Investigating unusual requests and activity in greater detail
- Rotating all potentially affected secret keys as a precaution
- Continuing enhanced monitoring after the initial review was completed
- Verifying that the affected component could not provide access to customer data
After completing this work, we have found zero evidence that the vulnerability was exploited or that Inline Manual was affected.
We are therefore marking this incident as resolved. We will continue to follow our normal security monitoring processes and will take further action if any new information becomes available.
Thank you,
Marek and the team
Aug 5, 23:13 CEST
We have completed our investigation into the potential impact of CVE-2026-66066.
We took a deliberately thorough approach and went beyond our standard review process to ensure we had examined every relevant source of information. This included:
- Patching the affected systems immediately
- Reviewing application, infrastructure, and access logs covering the relevant period
- Searching for known indicators and patterns associated with exploitation
- Investigating unusual requests and activity in greater detail
- Rotating all potentially affected secret keys as a precaution
- Continuing enhanced monitoring after the initial review was completed
- Verifying that the affected component could not provide access to customer data
After completing this work, we have found zero evidence that the vulnerability was exploited or that Inline Manual was affected.
We are therefore marking this incident as resolved. We will continue to follow our normal security monitoring processes and will take further action if any new information becomes available.
Thank you,
Marek and the team
Aug 5, 23:13 CEST
Update -
We are continuing to review our logs for any signs that CVE-2026-66066 was exploited before our systems were patched.
So far, we have found no evidence of malicious activity related to this vulnerability. Our rapid response appears to have prevented any exploitation, and we have also rotated all affected secret keys as an additional precaution.
Importantly, even if an attacker had attempted to exploit this vulnerability, it would not have given them access to customer data. We have confirmed this based on how the affected component is isolated within our infrastructure.
We will continue reviewing the logs and monitoring for any suspicious activity over the weekend. We will publish another update sooner if we identify anything relevant, or by Monday, August 3 at the latest if there are no new findings.
Jul 31, 21:08 CEST
So far, we have found no evidence of malicious activity related to this vulnerability. Our rapid response appears to have prevented any exploitation, and we have also rotated all affected secret keys as an additional precaution.
Importantly, even if an attacker had attempted to exploit this vulnerability, it would not have given them access to customer data. We have confirmed this based on how the affected component is isolated within our infrastructure.
We will continue reviewing the logs and monitoring for any suspicious activity over the weekend. We will publish another update sooner if we identify anything relevant, or by Monday, August 3 at the latest if there are no new findings.
Jul 31, 21:08 CEST
Investigating -
We are aware of the recently disclosed vulnerability CVE-2026-66066 and are treating it seriously.
Our production systems have already been patched. We are now conducting a thorough forensic review of relevant logs to confirm whether there was any attempt to exploit the vulnerability before the patch was applied.
At this stage, we have found no evidence that Inline Manual was affected. We are continuing the investigation as a precaution and will share another update once the review is complete.
[CVE-2026-66066] Possible arbitrary file read and remote code execution in Active Storage variant processing - https://discuss.rubyonrails.org/t/cve-2026-66066-possible-arbitrary-file-read-and-remote-code-execution-in-active-storage-variant-processing/91432
Jul 31, 13:27 CEST
Our production systems have already been patched. We are now conducting a thorough forensic review of relevant logs to confirm whether there was any attempt to exploit the vulnerability before the patch was applied.
At this stage, we have found no evidence that Inline Manual was affected. We are continuing the investigation as a precaution and will share another update once the review is complete.
[CVE-2026-66066] Possible arbitrary file read and remote code execution in Active Storage variant processing - https://discuss.rubyonrails.org/t/cve-2026-66066-possible-arbitrary-file-read-and-remote-code-execution-in-active-storage-variant-processing/91432
Jul 31, 13:27 CEST
Aug 4, 2026
No incidents reported.
Aug 3, 2026
No incidents reported.
Aug 2, 2026
No incidents reported.
Aug 1, 2026
No incidents reported.
Jul 31, 2026
Jul 30, 2026
No incidents reported.
Jul 29, 2026
No incidents reported.
Jul 28, 2026
No incidents reported.
Jul 27, 2026
No incidents reported.
Jul 26, 2026
No incidents reported.
Jul 25, 2026
No incidents reported.
Jul 24, 2026
No incidents reported.
Jul 23, 2026
No incidents reported.
