CVE-2026-59726: Ruflo RCE & AI Memory Flaw
🔴 Critical | Source: The Hacker News A critical vulnerability (CVE-2026-59726, CVSS 10.0) in Ruflo, an open-source AI agent harness for Claude Code and OpenAI Codex, allows unauthenticated attackers to execute arbitrary commands remotely. The flaw also enables AI memory poisoning via the Model Context Protocol (MCP), meaning attackers could manipulate the AI agent’s context and behaviour. All versions prior to 3.16.3 are affected, making immediate patching essential for any team running Ruflo in their AI development pipelines. ...