Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Ruby on Rails has released security updates for a critical Active Storage vulnerability that can allow an unauthenticated attacker to read arbitrary files from an application server through crafted image uploads. Tracked as CVE-2026-66066 and rated 9.5 on the CVSS scale, the flaw can expose secrets accessible to the Rails process and potentially enable remote […] The post CVE-2026-66066: Critical Rails Flaw Exposes Server Files via Image Uploads appeared first on SOC Prime.
<img width="400" height="234" src="https://socprime.com/wp-content/uploads/CVE-2026-66066-400x234.
Broadcom released emergency updates for a critical VMware ESXi vulnerability, CVE-2026-47876, that enables VM escape and code execution on the hypervisor host. The flaw, rated 9.3 CVSS, resides in the VMXNET3 network adapter and requires guest administrative access.
Broadcom has released emergency security updates for a critical VMware ESXi vulnerability that can allow an attacker to escape from a virtual machine and execute code on the underlying hypervisor host. Tracked as CVE-2026-47876 and rated 9.3 on the CVSS scale, the issue resides in the VMXNET3 network adapter.
This article details a critical vulnerability in VMware ESXi, tracked as CVE-2026-47876. The flaw is an out-of-bounds write in the VMXNET3 network adapter that could allow an attacker with local administrative privileges on a guest VM to escape to the hypervisor host.
<img width="400" height="234" src="https://socprime.com/wp-content/uploads/CVE-2026-47876-400x234.