
Critical Ruflo Flaw Lets Hackers Steal API Keys and Control Autonomous Agents
A critical unauthenticated remote code execution (RCE) vulnerability has been disclosed in the open-source AI agent orchestration platform Ruflo, exposing thousands of deployments to full system compromise. Tracked as CVE-2026-59726 and dubbed “RufRoot,” the flaw carries a maximum CVSS score of 10.0 and affects Ruflo’s MCP Bridge component, which fails to enforce authentication on sensitive […]
The post Critical Ruflo Flaw Lets Hackers Steal API Keys and Control Autonomous Agents appeared first on Cyber Security News.