Critical vulnerability in Ruflo AI agent platform allows unauthenticated attacker control Noma Security researchers disclosed CVE-2026-59726, a critical vulnerability in the open-source Ruflo AI agent platform that allows unauthenticated attackers to take full control of enterprise environments via an unprotected Model Context Protocol (MCP) bridge. The flaw poses significant risks as AI agent deployments expand into financial and operational workflows in regulated sectors. Critical vulnerability in Ruflo AI agent platform allows unauthenticated attacker control According to CSO Online, Noma Security researchers disclosed CVE-2026-59726, a critical flaw in the open-source Ruflo AI agent platform that exposes an unprotected Model Context Protocol MCP bridge. The vulnerability permits unauthenticated attackers to take full control of enterprise environments running the platform. The disclosure comes as enterprise AI agent deployments expand into financial and operational workflows across regulated sectors. Topics Sources - Press Read article https://www.csoonline.com/article/4203408/critical-ruflo-flaw-lets-attackers-hijack-ai-agents-through-exposed-mcp-bridge/ Go deeper This intelligence is sourced automatically from public sources across the web and synthesised by the Prefactor AI pipeline. Stories are reviewed before publication.