started · updated
Ruflo AI Platform and Check Point SmartConsole Hit by Critical Zero-Day Flaws
Security researchers disclosed two high‑severity zero‑day vulnerabilities. Noma Labs identified CVE‑2026‑59726 in the open‑source Ruflo AI agent orchestration platform, a CVSS 10.0 flaw that allows an unauthenticated attacker to execute arbitrary commands via the Model Context Protocol bridge and poison the platform’s persistent AI memory. The attack chain can steal LLM provider API keys, deploy backdoors and inject malicious patterns that affect future AI outputs.
Check Point Software Technologies reported CVE‑2026‑16232, a CVSS 9.3 authentication bypass in its SmartConsole management interface. The bug lets an unauthenticated attacker obtain full administrator rights on the management plane by exploiting a mis‑validated Secure Internal Communication identity. Rapid7 released a public proof‑of‑concept, confirming active exploitation against a handful of customers when the management server is exposed without IP restrictions.
Entities
Check Point Software Technologies Ltd. · Eli Ainhorn · Noma Labs · Rapid7 · Ruflo