CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

CVE-2026-59726: Critical Ruflo MCP Flaw Allows Unauthenticated RCE and AI Memory Poisoning

July 29, 2026

CVE-2026-59726 is a maximum-severity vulnerability (CVSS 10.0) in Ruflo, an open-source AI multi-agent orchestration platform. It allows unauthenticated attackers to achieve remote code execution via an exposed MCP bridge, leading to LLM API key theft, AI memory poisoning, and persistent backdoor deployment. All versions before 3.16.3 are affected.