Home / Jul 30, 2026 / Story
0
#8 The Hacker News general July 29, 2026 at 15:39 UTC

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

By [email protected] (The Hacker News)

AI Summary

Noma Security disclosed CVE-2026-59726 (CVSS 10.0), dubbed RufRoot, a maximum-severity unauthenticated remote code execution flaw in Ruflo, an open-source agent harness for Anthropic Claude Code and OpenAI Codex affecting all versions before 3.16.3. Beyond RCE, the vulnerability enables memory poisoning that can persist after patching, meaning AI agent behavior may remain corrupted even on updated systems. Any organization using Ruflo in agentic AI pipelines should update immediately and audit for signs of persistent compromise.

Relevance score: 79.0/100

# More from July 30