Ruby on Rails has patched CVE-2026-66066, a critical vulnerability leading to unauthenticated file reads and potentially RCE.