Dossier
CVE-2026-59726
Coverage of CVE-2026-59726 in the Nexus archive.
- Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory
Cybersecurity researchers identified a critical security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, allowing unauthenticated remote code execution. The vulnerability, CVE-2026-59726 (CVSS score: 10.0), affects versions before 3.16.3 and was codenamed RufRoot by Noma Security.