12:29
2026-07-30
csoonline.com
ai-safety
Critical Ruflo flaw lets attackers hijack AI agents through exposed MCP bridge
A critical vulnerability in the open-source AI agent platform Ruflo, tracked as CVE-2026-59726 and dubbed RufRoot, carries a maximum CVSS score of 10.0 and allows unauthenticated attackers to execute โฆ