Skip to content

Ruflo MCP: Critical RCE Vulnerability Enables Unlimited Code Execution

Bottom line: CVE-2026-59726 (CVSS 10.0) in Ruflo versions before 3.16.3 allows unlimited code execution without authentication.

A maximum severity vulnerability in Ruflo, an open-source orchestration solution for Claude Code and OpenAI Codex, enables unauthenticated attackers to achieve remote code execution. The flaw affects all versions prior to 3.16.3.

Cybersecurity researchers have identified a maximum-severity vulnerability in the Ruflo project. Ruflo is an open-source agent meta-harness for orchestrating Anthropic Claude Code and OpenAI Codex. The vulnerability carries the designation CVE-2026-59726 and has a CVSS score of 10.0 — the highest possible rating for critical security flaws.

The vulnerability affects all versions of Ruflo prior to version 3.16.3. Security researchers from Noma Security have designated the flaw with the codename RufRoot. It allows attackers without authentication to execute arbitrary commands and thereby potentially manipulate the memory state of the AI system.

For CISOs, this represents an immediate risk in production environments that use Ruflo for AI agent management. The availability of PoC code and the lack of authentication significantly lower the barrier to attack. Organizations should immediately verify which Ruflo versions are in use and perform an upgrade to 3.16.3 or newer.


Source: thehackernews.com · Published 29 July 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: