daily cyber × ai intelligence

index

tagged

[CVE-2026-59726]

1 edition · 1 item

July 30, 2026

  • "RufRoot" (CVE-2026-59726, CVSS 10.0) is an unauthenticated RCE in Ruflo, an open-source agent meta-harness for Claude Code and OpenAI Codex, disclosed by Noma Security. The bug lives in Ruflo's MCP bridge and lets attackers run commands with no login; researchers note it also enables persistent memory poisoning — malicious instructions can survive patching if compromised agent memory is retained, so agents keep following attacker-controlled directives. All versions before 3.16.3 are affected; ~233 downstream AI tools are reportedly exposed. The Hacker News, Dark Reading · AI & Model Security

in OpenAI's Rogue Agent Widens: Four More Companies Caught in the Blast Radius