CVE-2026-59726Disclosure

CRITICALCVSS 10.0 · CRITICAL

Exploitation observed; activity peaked at 12 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Ruflo is an agent meta-harness for Claude Code and Codex. Prior to 3.16.3, ruflo's default docker-compose deployment exposed the MCP bridge POST /mcp and POST /mcp/:group endpoints without authentication, allowing an unauthenticated network attacker to invoke tools/call to terminal_execute, obtain a shell in the bridge container, read provider API keys, and poison AgentDB learning-store patterns. This issue is fixed in version 3.16.3.

8.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78CWE-306CWE-942

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Threat summary

  • Active exploitation appears in 7 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 48 mentions across 16 observed days

What's happening

  • Active exploitation reported across 7 signals
  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 10 signals
  • Patch or workaround mentioned in 25 signals
  • Technical details provided in 45 signals
  • Disclosure: 17 classified signals
  • Peaked 12d ago at 12 mentions (2026-07-30); latest day: 1
  • 48 total mentions across 16 days

Deep dive

Activity timeline48 mentions / 16d
036912Mentions · 2026-07-09: 2Mentions · 2026-07-10: 3Mentions · 2026-07-29: 7Mentions · 2026-07-30: 12Mentions · 2026-07-31: 5Mentions · 2026-08-01: 3Mentions · 2026-08-03: 2Mentions · 2026-08-04: 3Mentions · 2026-08-05: 2Mentions · 2026-08-06: 1Mentions · 2026-08-07: 2Mentions · 2026-08-08: 1Mentions · 2026-08-09: 1Mentions · 2026-08-18: 1Mentions · 2026-09-03: 2Mentions · 2026-09-15: 1PoC Mentioned / Linked · 2026-07-29: 1PoC Mentioned / Linked · 2026-07-30: 2PoC Mentioned / Linked · 2026-07-31: 2PoC Mentioned / Linked · 2026-08-01: 2PoC Mentioned / Linked · 2026-08-04: 1PoC Mentioned / Linked · 2026-08-07: 1PoC Mentioned / Linked · 2026-09-15: 1Exploit Tool / Code · 2026-07-29: 1Exploit Tool / Code · 2026-08-09: 1Active Exploitation · 2026-07-29: 2Active Exploitation · 2026-07-30: 1Active Exploitation · 2026-08-01: 2Active Exploitation · 2026-08-04: 1Active Exploitation · 2026-08-09: 1Patch / Workaround · 2026-07-10: 2Patch / Workaround · 2026-07-29: 4Patch / Workaround · 2026-07-30: 8Patch / Workaround · 2026-07-31: 3Patch / Workaround · 2026-08-01: 2Patch / Workaround · 2026-08-03: 1Patch / Workaround · 2026-08-04: 1Patch / Workaround · 2026-08-05: 2Patch / Workaround · 2026-08-06: 1Patch / Workaround · 2026-08-08: 1Technical Details · 2026-07-09: 2Technical Details · 2026-07-10: 3Technical Details · 2026-07-29: 7Technical Details · 2026-07-30: 11Technical Details · 2026-07-31: 5Technical Details · 2026-08-01: 3Technical Details · 2026-08-03: 1Technical Details · 2026-08-04: 3Technical Details · 2026-08-05: 2Technical Details · 2026-08-06: 1Technical Details · 2026-08-07: 1Technical Details · 2026-08-08: 1Technical Details · 2026-08-09: 1Technical Details · 2026-08-18: 1Technical Details · 2026-09-03: 2Technical Details · 2026-09-15: 107-0907-1007-2907-3007-3108-0108-0308-0408-0508-0608-0708-0808-0908-1809-0309-15
Signal classification6 categories
Disclosure
1735.4%
Patch
1429.2%
Active Exploitation
612.5%
General
510.4%
Exploit
36.3%
PoC
36.3%
Referenced assets28 URLs
By indicator
Classification over time
DateTotalLabels
2026-07-092
Disclosure2
2026-07-103
Disclosure2Patch1
2026-07-297
Active Exploitation2Disclosure2Exploit1Patch2
2026-07-3012
Active Exploitation1Disclosure4General2Patch5
2026-07-315
Disclosure2Patch2PoC1
2026-08-013
Active Exploitation2Disclosure1
2026-08-032
General1Patch1
2026-08-043
Active Exploitation1Disclosure1Patch1
2026-08-052
Exploit1Patch1
2026-08-061
Disclosure1
2026-08-072
Disclosure1PoC1
2026-08-081
Patch1
2026-08-091
Exploit1
2026-08-181
Disclosure1
2026-09-032
General2
2026-09-151
PoC1
Full discourse20 posts
  • Kotte@Gustafssonkotte
    Active Exploitation

    A 10.0 IN THE TOOL THAT ORCHESTRATES CLAUDE CODE AND CODEX. ONE HTTP REQUEST, FULL SHELL. CVE-2026-59726, nicknamed RufRoot. It hit Ruflo, an agent harness with 66,000 GitHub stars. How simple it was: - Default deployment exposed the MCP bridge to the whole network - 233 tools behind it, zero authentication - One of them runs shell commands - A single POST request gets you inside What the attacker walks out with: - Provider API keys - Every stored conversation - Write access to the agent's memory That last one is the problem. Keys get rotated. Containers get rebuilt. Poisoned entries in an agent's memory stay after the patch, because they are data, not code. You fixed the door. What walked through it is still in the filing cabinet. The takeaway worth saving: Patch the path, then audit the memory. Agent systems have two attack surfaces: the code that runs them, and the store they learn from. Incident response built for servers only covers the first. Fixed in 24 hours, version 3.16.3. Good vendor response. The mistake behind it was the ordinary one: bind to all interfaces, assume nobody is looking. If your agent stack was compromised for a week, would you know what it learned?

    Post summary

    CVE-2026-59726 permitted unauthenticated RCE in the Ruflo agent harness via a single POST request, enabling attackers to steal API keys and data. The vulnerability was actively exploited and patched within 24 hours in version 3.16.3.

    136148272.3K
    2.7K followersView on X
  • CiberBaur@BotBauR
    Patch

    🚨 Acaba de confirmarse: una vulnerabilidad de gravedad máxima en Ruflo, un agente de código abierto, permite la ejecución remota de código sin autenticación y la contaminación de la memoria de la IA. La vulnerabilidad, CVE-2026-59726, impacta todas las versiones del proyecto antes de la 3.16.3, y ha sido codenada como RufRoot por Noma Security. La vulnerabilidad se descubrió en Ruflo, un agente meta-harness para Anthropic Claude Code y OpenAI Codex, y podría resultar en la ejecución remota de código sin autenticación. El CVSS score es de 10.0, lo que indica una gravedad máxima. Se han expuesto registros y se han contaminado memorias de IA, lo que podría tener consecuencias graves para las empresas que utilizan este software. La vulnerabilidad se puede explotar sin autenticación, lo que la hace especialmente peligrosa. Hay un parche disponible para la versión 3.16.3, por lo que es importante que los usuarios actualicen su software lo antes posible. ¿Estás en riesgo? Revisa esto: actualiza a la versión 3.16.3 de Ruflo y verifica si has sido afectado. #Ciberseguridad #CVE #SeguridadDigital #PYMEsMX https://thehackernews.com/2026/07/ruflo-mcp-flaw-lets-unauthenticated.html

    Post summary

    A new critical CVE‑2026‑59726 in Ruflo allows unauthenticated remote code execution and AI memory contamination; a patch is available for version 3.16.3.

    2802863.4K
    631 followersView on X
  • pdnuclei-bot@pdnuclei_bot
    PoC

    🚨 CVE-2026-59726 - critical 🚨 ruflo MCP Bridge - Unauthenticated RCE via terminal_execute > ruflo MCP bridge (< 3.16.3) in its default docker-compose deployment exposes POST /mc... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-59726 @pdnuclei #NucleiTemplates #cve

    Post summary

    The tweet discloses CVE-2026-59726, an unauthenticated RCE in ruflo MCP Bridge versions prior to 3.16.3, and primarily shares a Nuclei template link for detection/PoC purposes.

    210134778
    1.3K followersView on X
  • Cytex@cytexsmb
    Patch

    The Ruflo vulnerability is what happens when convenience outpaces security in the AI stack. The MCP layer is becoming the new API gateway for AI infrastructure, treat it like one. CVE-2026-59726 is a CVSS 10.0 flaw in an open-source agent orchestration platform with 67,000 GitHub stars. The MCP bridge exposed 233 tools including shell execution, over HTTP with no authentication. One unauthenticated POST request gave full command execution inside the container. The full impact chain is brutal: API key theft, agent weaponization, AI memory poisoning, conversation harvesting, and a persistent backdoor. The poisoned memory would steer future AI outputs across the entire platform. Users would have no way to tell the AI was compromised. Ruflo fixed it within 24 hours, but the lesson isn't about patching speed. It's about the default configuration. Port 3001 bound to 0.0.0.0, no authentication, and MongoDB with no password. This was the out-of-box experience for 1 million active users. If your MCP bridge is exposed to the network without authentication, treat it as a critical security boundary, not an auxiliary debug interface. For security teams adopting AI orchestration platforms, how are you auditing MCP bridges for authentication and tool restrictions before deployment?

    Post summary

    The post discloses CVE‑2026‑59726, a critical RCE flaw in Ruflo’s MCP bridge, notes rapid patching within 24 hours, and urges users to address the unprotected default configuration.

    2313377
    848 followersView on X
  • CloudSecurityAlliance@cloudsa
    Exploit

    CISO Daily Briefing: npm's keyv worm hijacked a maintainer account, hitting deps with 500M+ downloads/mo; Ruflo's MCP bridge had an unauth'd CVSS 10 RCE (CVE-2026-59726), patched but rogue policies persist; LiteLLM callback hooks enable tool-call hijacking, no patch exists. Four supply-chain breaks (npm, Adform, RubyGems, JFrog) in 2 weeks show systemic concentration risk. Gov: H.R. 9917 would give DHS shutdown authority over frontier AI. https://labs.cloudsecurityalliance.org/research/ciso-daily-briefing-20260805/

    Post summary

    The briefing reports several supply‑chain attacks, including a patched CVE‑2026‑59726 RCE and unpatched LiteLLM callback issues, highlighting ongoing exploitation risks despite mitigation efforts.

    02032576
    18.9K followersView on X
  • omnipotent@omnipotentblock
    Patch

    🚨 Critical AI Security Alert: Ruflo MCP Exposure (CVE-2026-59726) A critical vulnerability (CVSS 10.0) was discovered in Ruflo's default MCP deployment, where an unauthenticated MCP bridge exposed powerful tools including terminal execution to anyone with network access. An attacker could: • Achieve unauthenticated RCE • Steal LLM API keys • Read stored conversations • Poison persistent AI memory • Deploy malicious AI agent swarms Affected: Ruflo < v3.16.3 If you're running Ruflo, patch immediately, restrict exposed ports, rotate API keys, and audit your AI memory store for signs of compromise. AI infrastructure deserves the same security rigor as production systems.

    Post summary

    The text announces CVE‑2026‑59726, details the severe unauthenticated RCE and associated risks for Ruflo users, and urges immediate patching and security hardening.

    00060177
    51 followersView on X
  • Eiji Sasahara 笹原英司 (he/him)@esasahara
    Disclosure

    RufRoot: The MCP Bridge Vulnerability That Turns Agents Into Rogue Admins (CVE-2026-59726) - Noma Security https://noma.security/blog/rufroot-the-mcp-bridge-vulnerability-that-turns-agents-into-rogue-admins-cve-2026-59726/

    Post summary

    The provided text announces a new vulnerability (CVE‑2026‑59726) without revealing PoC, exploitation details, patches, or technical specifics.

    01031658
    861 followersView on X
  • Alex C@AlexanderChopra
    Exploit

    🚨 Critical AI agent platform flaw (CVE-2026-59726) — and the worst part isn’t the RCE. How many of you have actually audited the MCP endpoints and persistent memory stores on your local/self-hosted agent setups this week? #CyberSecurity #AI #Infosec #MCP Ruflo (popular open-source agent meta-harness for Claude Code & Codex swarms, ~66k GitHub stars) shipped with its MCP bridge exposed by default and zero authentication. Root cause: Default docker-compose.yml bound the MCP bridge (and MongoDB) to 0.0.0.0. The endpoints POST /mcp and POST /mcp/:group accepted JSON-RPC tools/call requests with no auth middleware. The server-side tool blocklist that was supposed to restrict terminal_execute only applied inside the autopilot flow. Direct HTTP calls to the bridge bypassed it completely. What an unauthenticated attacker could do with one request: 1) Call tools/call → terminal_execute (or the namespaced variant) and get a shell as the node user (UID 1000) inside the bridge container. 2) Read every provider API key sitting in the container environment (printenv, env, etc.). 3) Use those keys to spawn attacker-controlled agent swarms on the victim’s quota. 4) Write poisoned entries into the AgentDB learning-store / pattern store. These patterns persist and can steer future agent behavior for every user of that instance. That last point is the real problem. Memory/pattern poisoning survives a simple patch + redeploy. You must explicitly audit and purge the store. Illustrative request structure (MCP/JSON-RPC style that the bridge accepted): { "jsonrpc": "2.0", "method": "tools/call", "params": { "name": "terminal_execute", "arguments": { "command": "id; printenv | grep -E 'KEY|TOKEN|API|SECRET'" } }, "id": 1 } No credentials required on a default deployment. The bridge treated the network as trusted. Why this is more dangerous than a normal RCE: Traditional RCE ends when you rotate keys and patch. Here the attacker can leave persistent behavioral influence inside the agent’s memory layer. That is a new integrity failure mode for agent platforms. Full technical advisory: https://github.com/ruvnet/ruflo/security/advisories/GHSA-c4hm-4h84-2cf3 Noma Labs disclosure: https://www.prnewswire.com/news-releases/noma-labs-discovers-critical-vulnerability-in-widely-adopted-open-source-ai-agent-platform-ruflo-302837494.html How many of you have actually audited the MCP endpoints and persistent memory stores on your local/self-hosted agent setups this week? #CyberSecurity #AI #Infosec #MCP

    Post summary

    CVE‑2026‑59726 enables unauthenticated attackers to execute commands and poison agent memory via the MCP bridge; the advisory outlines remediation steps but does not report active exploitation.

    30011252
    9 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨Critical - Ruflo Unauthenticated MCP Bridge RCE & API-Key Theft (CVE-2026-59726) Ruflo - an agent meta-harness for Claude Code and Codex - shipped a default Docker Compose deployment that exposed the MCP bridge endpoints POST /mcp and POST /mcp/:group with no authentication. An unauthenticated network attacker can invoke tools/call to the terminal_execute tool to obtain a shell in the bridge container. From there they can read provider API keys and poison AgentDB learning-store patterns - combining unauthenticated RCE, credential theft, and agent-behavior tampering. It's a maximum-severity CVSS 10.0, CISA-assessed automatable. 👉Upgrade Ruflo to 3.16.3.

    Post summary

    The post discloses that CVE‑2026‑59726 allows an unauthenticated attacker to execute commands and steal API keys via Ruflo’s MCP bridge, with a CVSS score of 10.0, and recommends upgrading to version 3.16.3 to remediate.

    20021232
    300 followersView on X
  • Jack — building in public@itsjackdev
    Disclosure

    and right on cue, while i was writing this: ruflo, 67k stars, shipped an mcp bridge that exposed 233 agent tools over http with no auth. one POST, full RCE, every key. the loaded gun wasn't even in a drawer. CVE-2026-59726. https://t.co/RdwdbTvBVi

    Post summary

    The tweet discloses CVE‑2026‑59726, detailing a full remote code execution flaw in an MCP bridge that exposes 233 agent tools over HTTP with no authentication.

    02020376
    46 followersView on X
  • ボス@サイバーセキュリティの専門家@boss_sec_labo
    Exploit

    CVSS 10.0の認証なし穴が1本走った。バックドアが仕込まれたルーターが10万台ネットにある。Salesforceデータなど4700万件超の窃取が主張された。 君の現場の「信頼しているもの」を一度疑え。 ・RufRoot CVE-2026-59726、AI基盤MCPにCVSS 10.0の認証不要RCE ・XSS2Shell CVE-2026-64638、WordPressで未認証XSSがRCEに連鎖(5億超) ・Zbtlinkルーター20機種に中国向けバックドア「ENDLESSDOORS」 ・Metabaseゼロデイ積極悪用、顧客データ窃取被害 ・ShinyHuntersがSalesforceデータなど4700万件超の窃取を主張・3社を脅迫 君が使っているAIツール・BIツール・SaaS、そのどれかに今日と同じ穴がある。 それを誰が管理しているか、すぐ答えられるか? 管理者不在の外部連携は、攻撃者にとって最も静かな入口だ。

    Post summary

    The post lists multiple zero‑day exploits with CVSS 10.0, including active RCE usage and data theft, but does not provide actual code or patches.

    00031444
    1.4K followersView on X
  • GetAIGovernance@getaigovernance
    General

    RufRoot: Critical MCP Bridge Vulnerability in Ruflo Turns AI Agents into Rogue Admins (CVE-2026-59726) @NomaSecurity https://getaigovernance.net/blog/rufroot-mcp-bridge-cve-2026-59726

    Post summary

    The tweet announces a blog post about CVE-2026-59726, a critical vulnerability in Ruflo's MCP Bridge that could elevate AI agents to rogue administrators, but it offers no detailed technical information, PoC, or exploitation evidence.

    10030134
    8 followersView on X
  • Sam Stepanyan@securestep9
    Disclosure

    #AI: RufRoot a Critical (CVSS 10) MCP bridge vulnerability in #Ruflo, an open source AI agent orchestration platform with 67,000+ GitHub stars and ranked #2 on MCPMarket turns AI Agents into Rogue Admins: #AISecurity 👇 https://noma.security/blog/rufroot-the-mcp-bridge-vulnerability-that-turns-agents-into-rogue-admins-cve-2026-59726/

    Post summary

    A blog post announces the discovery of a critical CVE-2026-59726 vulnerability in the Ruflo MCP bridge that could turn AI agents into rogue admins, but no PoC, exploit code, or active exploitation details are provided, and no patch information is discussed.

    00040414
    7.4K followersView on X
  • AI Security Brief@aisecbrief
    Patch

    Ruflo agent flaw (CVE-2026-59726) has CVSS 10.0. Unauthenticated RCE possible. Attackers can run commands &amp; poison AI memory in Ruflo. It affects open-source agents for Claude &amp; Codex. Patch Ruflo to v3.16.3 ASAP. #AISecurity #InfoSec 🔗 Source in replies

    Post summary

    CVE-2026-59726 is an unauthenticated RCE flaw with CVSS 10.0 in Ruflo agents for Claude and Codex, and users are urged to update to version 3.16.3 immediately.

    2000157
    6 followersView on X
  • Diario฿itcoin@DiarioBitcoin
    Patch

    🚨 Falla crítica en Ruflo expone agentes de IA a control no autorizado 🚨 Vulnerabilidad CVE-2026-59726 permite ejecutar comandos sin autenticación. Impacto severo en claves API y memoria de agentes. Actualización a versión 3.16.3 es urgente. La seguridad de los sistemas autónomos se ve comprometida. Requiere atención inmediata para proteger la información y funciones.

    Post summary

    A critical vulnerability (CVE‑2026‑59726) permits unauthenticated command execution against Ruflo agents, impacting API keys and memory. Updating to version 3.16.3 is urgently advised to mitigate the risk.

    11010850
    213.3K followersView on X
  • kokumօtօ@__kokumoto
    Patch

    Ruflo(旧Claude Flow)でCVSSスコア10の脆弱性"RufRoot" (CVE-2026-59726)が修正。既定のDocker Compose構成でデプロイされた場合に脆弱。認証無しでMCPツールを露出しているのが悪い。パッチしても汚染されたメモリは残ることに留意。 https://hackread.com/rufroot-vulnerability-attackers-hijack-ruflo-login/

    Post summary

    The text announces that CVE‑2026‑59726 (RufRoot) with a CVSS 10 score has been fixed in Ruflo, provides technical details on the flaw, and notes a patching caveat, but does not mention exploits or active attacks.

    00030945
    7.8K followersView on X
  • Fiona@fiona_novesai
    Patch

    Ruflo: 67K stars, CVSS 10.0. CVE-2026-59726: MCP Bridge has zero auth on tool-execution endpoints. One HTTP request = shell access + API key theft. Your agent's bridge to 200+ tools just became an attacker's bridge. Patch: 3.16.3. Bind to localhost. Verify before you star.

    Post summary

    CVE-2026-59726 allows unauthenticated remote code execution via MCP Bridge tool-execution endpoints; mitigation involves upgrading to patch 3.16.3 and binding the bridge to localhost.

    2001078
    12 followersView on X
  • Evan Kirstel #B2B #TechFluencer@EvanKirstel
    Disclosure

    CVE-2026-59726, CVSS 10.0. An unauthenticated POST to port 3001 ran arbitrary commands on Ruflo's MCP bridge. 233 tools exposed with no auth, every LLM provider key readable from the container env. 66,500 GitHub stars. Patched in 24 hours. https://noma.security/blog/rufroot-the-mcp-bridge-vulnerability-that-turns-agents-into-rogue-admins-cve-2026-59726/

    Post summary

    The post announces CVE‑2026‑59726, highlights a critical unauthenticated command injection on Ruflo’s MCP bridge, and notes rapid patch availability within 24 hours.

    01010620
    386.0K followersView on X
  • Xavier Rivera@XavierRiveraX
    Disclosure

    Noma Security found CVE-2026-59726, a CVSS 10.0 unauthenticated RCE in Ruflo, the open-source harness for Claude Code and Codex agents. Attackers could run arbitrary commands and poison agent memory on any version before 3.16.3. Update now if you run agentic coding tools.

    Post summary

    Noma Security disclosed CVE-2026-59726, a critical unauthenticated RCE in Ruflo affecting versions before 3.16.3, enabling arbitrary command execution; users are urged to update immediately.

    10010104
    601 followersView on X
  • SS@echonerve_
    Patch

    2/ CVE-2026-59726, "RufRoot," disclosed June 30 inside Ruflo's MCP Bridge. Default Docker config, no auth, 233 tools reachable. Patched in 24 hours — but the patch just adds a password. No human checkpoint anywhere in that path.

    Post summary

    CVE-2026-59726 ("RufRoot") was disclosed June 30 involving a default Docker configuration lacking authentication, exposing 233 tools; a patch adding a password was released within 24 hours.

    1000049
    379 followersView on X

Explore more