Login
← All news

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

The Hacker News

Cybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, that could result in unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-59726 (CVSS score: 10.0), impacts all versions of the project before version 3.16.3. It has been codenamed RufRoot by Noma Security's

Read the full story on The Hacker News https://thehackernews.com/2026/07/ruflo-mcp-flaw-lets-unauthenticated.html
Most attacks like this land on ordinary sites rather than chosen targets: an unpatched plugin, a backup nobody ever restored, an account without two-factor. If you would rather your site never became the story, CrockyHost hosting ships with daily backups, automatic updates and a firewall we manage for you.