< Back to situations

This situation has concluded

It was preserved as a record on September 1; the timeline below shows how it unfolded, with sources. Get the briefing to follow the top situations still developing: three emails a week, sourced and in order.

[SITUATION] · [QUIET] · [TECHNOLOGY]

2 clusters · 6 sources · 4 days · First seen · Last updated

Critical zero‑day flaws in Ruflo AI platform

Overview

On 29 July 2026 researchers disclosed a critical vulnerability (CVE‑2026‑59726) in Ruflo’s Model Context Protocol Bridge, rating 10.0 on the CVSS scale. The flaw permits an unauthenticated attacker to send a crafted HTTP POST to the /mcp endpoint, gaining arbitrary shell execution inside the container and access to 233 exposed tools, including the terminal execution tool. Exploitation can exfiltrate API keys for major LLM providers, hijack AI agent swarms, and poison the platform’s persistent memory. The advisory recommended upgrading to Rufio version 3.16.3, restricting the bridge to localhost, enabling token‑based authentication, rotating credentials and blocking the vulnerable ports.

Two days later, on 1 August 2026, the same CVE‑2026‑59726 was reiterated alongside a second high‑severity zero‑day (CVE‑2026‑16232) affecting Check Point’s SmartConsole management interface. The Check Point flaw, scored 9.3, allows unauthenticated attackers to bypass authentication and obtain full administrator rights when the management server is exposed without IP restrictions. A public proof‑of‑concept released by Rapid7 confirmed active exploitation against a limited set of customers. The combined report highlighted that both vulnerabilities were being actively targeted and underscored the urgency of applying the recommended patches and network‑level mitigations.

Entities

Noma Labs · Ruflo · Ram Varadarajan · Model Context Protocol Bridge · OpenAI

Timeline

  1. about 2 months ago

    [TECHNOLOGY] 2 sources
    Ruflo AI Platform and Check Point SmartConsole Hit by Critical Zero-Day Flaws

    Critical zero‑day flaws were disclosed in Ruflo’s AI platform (remote code execution and AI memory poisoning) and Check Point’s SmartConsole (authentication bypass granting admin access).

  2. about 2 months ago

    [TECHNOLOGY] 4 sources
    Ruflo AI Orchestration Platform Exposes Critical CVE-2026-59726 Flaw

    A critical CVE‑2026‑59726 flaw in Ruflo’s MCP Bridge (CVSS 10.0) lets unauthenticated attackers execute commands, steal AI provider keys and tamper with persistent agent memory; it impacts pre‑3.16.3 Docker‑de​

Sources

blogspan.net · cybersecuritynews.com · dev.to · forkast.news · hackread.com · latesthackingnews.com