Rapid7 emerging-threat writeup of CVE-2026-66066 (KindaRails2Shell). Confirms CVSSv4 9.5, CWE-1188 insecure default. Affects apps using libvips variant processor with untrusted uploads. Magick processor not affected via this vector. No known in-the-wild exploitation as of July 30, 2026. Patch matrix and secret-rotation guidance aligned with Rails advisory.