RufRoot (CVE-2026-59726): Full Compromise of AI Agent Infrastructure via Unauthenticated MCP...

The flaw in the AI hosting platform Ruflo allows an unauthenticated attacker to take over and corrupt memory, so bad behavior persists after patching.

Ruflo CVE-2026-59726 exposes an unauthenticated MCP bridge that could enable RCE, LLM key theft, conversation access, and AI memory poisoning.