VulnWatch VulnWatch
← Back to dashboard
Unknown rss_thehackernews · rss_19447019942cf67fe9b4bce83bb03668

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

Published Jul 29, 2026

Cybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, that could result in unauthenticated remote code execution.

The vulnerability, tracked as CVE-2026-59726 (CVSS score: 10.0), impacts all versions of the project before version 3.16.3. It has been codenamed RufRoot by Noma Security's

Affected AI Products

claude code anthropic openai claude
Get the weekly digest. Every Monday: top AI security stories of the week. Free.