#8
The Hacker News
general
July 29, 2026 at 15:39 UTC
Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory
By [email protected] (The Hacker News)
AI Summary
Noma Security disclosed CVE-2026-59726 (CVSS 10.0), dubbed RufRoot, a maximum-severity unauthenticated remote code execution flaw in Ruflo, an open-source agent harness for Anthropic Claude Code and OpenAI Codex affecting all versions before 3.16.3. Beyond RCE, the vulnerability enables memory poisoning that can persist after patching, meaning AI agent behavior may remain corrupted even on updated systems. Any organization using Ruflo in agentic AI pipelines should update immediately and audit for signs of persistent compromise.
Relevance score: 79.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →