EventCybersecurityJuly 29, 2026

Critical Ruflo MCP flaw allows unauthenticated RCE and AI memory poisoning

A maximum-severity vulnerability in the open-source AI agent harness Ruflo (CVE-2026-59726, CVSS 10.0) allows unauthenticated attackers to execute arbitrary commands and poison AI memory via HTTP requests to an exposed endpoint. The flaw can be used to spawn malicious AI agent swarms, and corrupts memory in a way that can persist after patching.

How this story unfolded

1 day · 3 reports · from Jul 29

  1. Jul 29
  2. Jul 30

More stories today

Open the live feed