Critical Ruflo Vulnerability Allows Full Control of AI Agent Platforms

Critical Ruflo Vulnerability Allows Full Control of AI Agent Platforms

First seen 29 Jul 2026, 17:15 UTC PrnewswireGbhackersDarkreadingCybersecuritynewsThehackernews+7 85% similarity 72.6

Article Content

Browse articles
ThreatCluster

Noma Labs has disclosed a critical vulnerability (CVE-2026-59726) in the Ruflo AI hosting platform, allowing unauthenticated attackers to execute arbitrary commands and take full control of AI agent environments. The flaw, known as 'RufRoot', has a maximum CVSS score of 10.0 and enables attackers to exploit a Model Context Protocol (MCP) bridge that is open by default. This vulnerability allows attackers to steal sensitive API keys, read user conversations, and tamper with the AI's memory, influencing future interactions. The vulnerability was responsibly disclosed on June 30, 2026, and Ruflo released a patch within 24 hours, locking down the platform's configuration. However, experts warn that simply patching the software does not guarantee safety, as compromised agents may still operate. Organizations are advised to rotate credentials and audit AI memory for tampering. The incident highlights the emerging risks associated with AI systems.

Key Points: • The Ruflo platform vulnerability allows full remote control with a single unauthenticated request. • Attackers can tamper with AI memory, influencing future responses even after the attack ends. • Organizations must audit AI memory and rotate credentials post-exploitation to mitigate risks.

ThreatCluster AI How this analysis works

Timeline

2026-06-30
Vulnerability disclosed to Ruflo maintainers
Noma Labs reported the critical flaw to Ruflo, including a proof-of-concept for exploitation.
Darkreading
2026-07-09
CVE-2026-59726 published
The vulnerability was officially published, tracking as CVE-2026-59726, with a CVSS score of 10.0.
N/A
2026-07-29
Ruflo releases patch
Ruflo responded to the vulnerability by releasing a patch that locks down the platform's configuration.
Prnewswire
2026-07-29
Noma Labs issues warning
Noma Labs emphasized that patching alone does not ensure safety from compromised AI agents.
Darkreading

Community

Browse all →