A critical Ruflo vulnerability allowed unauthenticated attackers to achieve remote code execution (RCE) inside the MCP bridge container.

The flaw in the AI hosting platform Ruflo allows an unauthenticated attacker to take over and corrupt memory, so bad behavior persists after patching.

Ruflo CVE-2026-59726 exposes an unauthenticated MCP bridge that could enable RCE, LLM key theft, conversation access, and AI memory poisoning.