Use cases
Software Products E-commerce MSPs Schools Development & Marketing DevOps Agencies Help Desk
Company
Internet Status Blog Pricing Log in Get started free

Outage in Inline Manual

Reviewing potential exposure to CVE-2026-66066

Resolved Minor
July 31, 2026 - Started 6 days ago - Lasted 5 days
Official incident page

Incident Report

We are aware of the recently disclosed vulnerability CVE-2026-66066 and are treating it seriously. Our production systems have already been patched. We are now conducting a thorough forensic review of relevant logs to confirm whether there was any attempt to exploit the vulnerability before the patch was applied. At this stage, we have found no evidence that Inline Manual was affected. We are continuing the investigation as a precaution and will share another update once the review is complete. [CVE-2026-66066] Possible arbitrary file read and remote code execution in Active Storage variant processing - https://discuss.rubyonrails.org/t/cve-2026-66066-possible-arbitrary-file-read-and-remote-code-execution-in-active-storage-variant-processing/91432

Trusted by 1,000+ teams

The Status Page Aggregator with Early Outage Detection

Stop finding out about outages from your users. Monitor 6,320+ cloud services and get alerted the second something breaks.

IsDown status aggregator dashboard
Latest Updates ( sorted recent to last )
RESOLVED about 4 hours ago - at 08/05/2026 09:13PM

Resolved - no evidence of exploitation

We have completed our investigation into the potential impact of CVE-2026-66066.

We took a deliberately thorough approach and went beyond our standard review process to ensure we had examined every relevant source of information. This included:

- Patching the affected systems immediately
- Reviewing application, infrastructure, and access logs covering the relevant period
- Searching for known indicators and patterns associated with exploitation
- Investigating unusual requests and activity in greater detail
- Rotating all potentially affected secret keys as a precaution
- Continuing enhanced monitoring after the initial review was completed
- Verifying that the affected component could not provide access to customer data

After completing this work, we have found zero evidence that the vulnerability was exploited or that Inline Manual was affected.

We are therefore marking this incident as resolved. We will continue to follow our normal security monitoring processes and will take further action if any new information becomes available.

Thank you,
Marek and the team

INVESTIGATING 5 days ago - at 07/31/2026 07:08PM

We are continuing to review our logs for any signs that CVE-2026-66066 was exploited before our systems were patched.

So far, we have found no evidence of malicious activity related to this vulnerability. Our rapid response appears to have prevented any exploitation, and we have also rotated all affected secret keys as an additional precaution.

Importantly, even if an attacker had attempted to exploit this vulnerability, it would not have given them access to customer data. We have confirmed this based on how the affected component is isolated within our infrastructure.

We will continue reviewing the logs and monitoring for any suspicious activity over the weekend. We will publish another update sooner if we identify anything relevant, or by Monday, August 3 at the latest if there are no new findings.

INVESTIGATING 6 days ago - at 07/31/2026 11:27AM

We are aware of the recently disclosed vulnerability CVE-2026-66066 and are treating it seriously.

Our production systems have already been patched. We are now conducting a thorough forensic review of relevant logs to confirm whether there was any attempt to exploit the vulnerability before the patch was applied.

At this stage, we have found no evidence that Inline Manual was affected. We are continuing the investigation as a precaution and will share another update once the review is complete.

[CVE-2026-66066] Possible arbitrary file read and remote code execution in Active Storage variant processing - https://discuss.rubyonrails.org/t/cve-2026-66066-possible-arbitrary-file-read-and-remote-code-execution-in-active-storage-variant-processing/91432

Latest Inline Manual outages

Authoring Tool Unavailable - over 2 years ago

The Status Page Aggregator with Early Outage Detection

With IsDown, you can monitor all your critical services' official status pages from one centralized dashboard and receive instant alerts the moment an outage is detected. Say goodbye to constantly checking multiple sites for updates and stay ahead of outages with IsDown.

Start free trial

No credit card required · Cancel anytime · 6320 services available

Integrations with Slack Microsoft Teams Google Chat Datadog PagerDuty Zapier Discord Webhook