EventCybersecurityJuly 29, 2026

Critical Ruflo MCP flaw allows unauthenticated RCE and AI memory poisoning

A maximum-severity vulnerability in the open-source AI agent harness Ruflo (CVE-2026-59726, CVSS 10.0) allows unauthenticated attackers to execute arbitrary commands and poison AI memory via HTTP requests to an exposed endpoint. The flaw can be used to spawn malicious AI agent swarms, and corrupts memory in a way that can persist after patching.

3 sources

Daily brief

Get tomorrow's AI brief in your inbox

More stories today

Open the live feed
Critical Ruflo MCP flaw allows unauthenticated RCE and AI memory poisoning — AIBriefs