5 min read
Vulnerabilities CVE-2026-59726, dubbed RufRoot, is a CVSS 10.0 flaw in Ruflo's MCP bridge that lets unauthenticated attackers execute shell commands, steal LLM API keys, and poison the platform's persistent AI memory store. Patch ships quickly; poisoned AgentDB entries do not self-clear.