Critical Ruflo MCP Bridge Flaw Lets Attackers Execute Commands and Hijack AI Agents

A critical security flaw in the open-source AI orchestration platform Ruflo has been disclosed, allowing unauthenticated attackers to execute arbitrary commands and fully compromise AI agent environments. Assigned a maximum CVSS base score of 10.0, the vulnerability (tracked as CVE-2026-59726) was discovered by Noma Labs and affects Ruflo’s Model Context Protocol (MCP) Bridge, a core […]

This article has been indexed from Cyber Security News

Read the original article: