vulnerability
Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory
A critical vulnerability (CVE-2026-59726) in Ruflo, an AI agent orchestration platform, allows unauthenticated remote code execution. Attackers can steal LLM API keys, harvest user conversations, and poison AI memory, le…
Critical
