Ruflo MCP flaw: unauthenticated remote command execution
A critical Ruflo MCP flaw (CVE-2026-59726) lets attackers run commands without authentication. The impact includes API key theft and poisoning of persistent AI memory.
A critical Ruflo MCP flaw (CVE-2026-59726) lets attackers run commands without authentication. The impact includes API key theft and poisoning of persistent AI memory.