CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3455

As cited

Copy frozen at (site build).

vulnerabilities

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

A critical vulnerability (CVE-2026-59726, CVSS 10.0) in Ruflo, an open-source agent framework for Anthropic Claude and OpenAI Codex, permits unauthenticated remote code execution across all versions prior to 3.16.3. Noma Security researchers identified the flaw, which they designated RufRoot.

Why it matters: Developers and organizations using Ruflo for AI agent deployments face immediate risk of code execution and data poisoning; patching to version 3.16.3 or later is required.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

Researchers disclosed a critical flaw in Ruflo, an open‑source meta‑harness for Claude Code and OpenAI Codex, that permits unauthenticated remote code execution. Tracked as CVE-2026-59726 with a CVSS score of 10.0, the vulnerability affects every release prior to version 3.16.3 and has been dubbed RufRoot.

Why it matters: Users of Ruflo versions earlier than 3.16.3 are exposed to unauthenticated remote code execution and should update to 3.16.3 or later immediately.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

Researchers disclosed a critical flaw in Ruflo, an open‑source meta‑harness for Claude Code and OpenAI Codex, that permits unauthenticated remote code execution. Tracked as CVE-2026-59726 with a CVSS score of 10.0, the vulnerability affects every release prior to version 3.16.3 and has been dubbed RufRoot.

Why it matters: Users of Ruflo versions earlier than 3.16.3 are exposed to unauthenticated remote code execution and should update to 3.16.3 or later immediately.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary