EventCybersecurityJuly 29, 2026

Ruflo MCP flaw allows unauthenticated remote code execution

CVE-2026-59726 (CVSS 10.0) impacts all versions of Ruflo, an open-source agent harness for Claude Code and Codex. The flaw enables unauthenticated RCE and AI memory poisoning.

1 source

Daily brief

Get tomorrow's AI brief in your inbox

More stories today

Open the live feed