Prnewswire Critical Ruflo Vulnerability Allows Full Control of AI Agent Platforms
Article Content
- •The Ruflo platform vulnerability allows full remote control with a single unauthenticated request.
- •Attackers can tamper with AI memory, influencing future responses even after the attack ends.
- •Organizations must audit AI memory and rotate credentials post-exploitation to mitigate risks.
Noma Labs has disclosed a critical vulnerability (CVE-2026-59726) in the Ruflo AI hosting platform, allowing unauthenticated attackers to execute arbitrary commands and take full control of AI agent environments. The flaw, known as 'RufRoot', has a maximum CVSS score of 10.0 and enables attackers to exploit a Model Context Protocol (MCP) bridge that is open by default. This vulnerability allows attackers to steal sensitive API keys, read user conversations, and tamper with the AI's memory, influencing future interactions. The vulnerability was responsibly disclosed on June 30, 2026, and Ruflo released a patch within 24 hours, locking down the platform's configuration. However, experts warn that simply patching the software does not guarantee safety, as compromised agents may still operate. Organizations are advised to rotate credentials and audit AI memory for tampering. The incident highlights the emerging risks associated with AI systems.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (12)
Following this threat?
Track Noma Labs and CVE-2026-59726 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
New Workflow Identity Hijacking Threat Discovered in AI Systems Researchers at Noma Security have identified a new attack vector called Workflow Identity Hijacking, which allows malicious actors to exploit AI workflows by sending benign requests through unauthenticated entry points. This attack does not manipulate the underlying AI model but instead circumvents standard security…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…