Update - We are continuing to review our logs for any signs that CVE-2026-66066 was exploited before our systems were patched.
So far, we have found no evidence of malicious activity related to this vulnerability. Our rapid response appears to have prevented any exploitation, and we have also rotated all affected secret keys as an additional precaution.
Importantly, even if an attacker had attempted to exploit this vulnerability, it would not have given them access to customer data. We have confirmed this based on how the affected component is isolated within our infrastructure.
We will continue reviewing the logs and monitoring for any suspicious activity over the weekend. We will publish another update sooner if we identify anything relevant, or by Monday, August 3 at the latest if there are no new findings.
Jul 31, 2026 - 21:08 CEST
So far, we have found no evidence of malicious activity related to this vulnerability. Our rapid response appears to have prevented any exploitation, and we have also rotated all affected secret keys as an additional precaution.
Importantly, even if an attacker had attempted to exploit this vulnerability, it would not have given them access to customer data. We have confirmed this based on how the affected component is isolated within our infrastructure.
We will continue reviewing the logs and monitoring for any suspicious activity over the weekend. We will publish another update sooner if we identify anything relevant, or by Monday, August 3 at the latest if there are no new findings.
Jul 31, 2026 - 21:08 CEST
Investigating - We are aware of the recently disclosed vulnerability CVE-2026-66066 and are treating it seriously.
Our production systems have already been patched. We are now conducting a thorough forensic review of relevant logs to confirm whether there was any attempt to exploit the vulnerability before the patch was applied.
At this stage, we have found no evidence that Inline Manual was affected. We are continuing the investigation as a precaution and will share another update once the review is complete.
[CVE-2026-66066] Possible arbitrary file read and remote code execution in Active Storage variant processing - https://discuss.rubyonrails.org/t/cve-2026-66066-possible-arbitrary-file-read-and-remote-code-execution-in-active-storage-variant-processing/91432
Jul 31, 2026 - 13:27 CEST
Our production systems have already been patched. We are now conducting a thorough forensic review of relevant logs to confirm whether there was any attempt to exploit the vulnerability before the patch was applied.
At this stage, we have found no evidence that Inline Manual was affected. We are continuing the investigation as a precaution and will share another update once the review is complete.
[CVE-2026-66066] Possible arbitrary file read and remote code execution in Active Storage variant processing - https://discuss.rubyonrails.org/t/cve-2026-66066-possible-arbitrary-file-read-and-remote-code-execution-in-active-storage-variant-processing/91432
Jul 31, 2026 - 13:27 CEST
About This Site
Here we will post updates about Inline Manual's service availability.
