# Critical zero‑day flaws in Ruflo AI platform

> Live situation record from CLSTR: https://clstr.news/situations/critical-zeroday-flaws-in-ruflo-ai-platform
> Updated: 2026-08-01T18:25:27.000Z. Sources: 6. Developments: 2.

On 29 July 2026 researchers disclosed a critical vulnerability (CVE‑2026‑59726) in Ruflo’s Model Context Protocol Bridge, rating 10.0 on the CVSS scale. The flaw permits an unauthenticated attacker to send a crafted HTTP POST to the /mcp endpoint, gaining arbitrary shell execution inside the container and access to 233 exposed tools, including the terminal execution tool. Exploitation can exfiltrate API keys for major LLM providers, hijack AI agent swarms, and poison the platform’s persistent memory. The advisory recommended upgrading to Rufio version 3.16.3, restricting the bridge to localhost, enabling token‑based authentication, rotating credentials and blocking the vulnerable ports.

Two days later, on 1 August 2026, the same CVE‑2026‑59726 was reiterated alongside a second high‑severity zero‑day (CVE‑2026‑16232) affecting Check Point’s SmartConsole management interface. The Check Point flaw, scored 9.3, allows unauthenticated attackers to bypass authentication and obtain full administrator rights when the management server is exposed without IP restrictions. A public proof‑of‑concept released by Rapid7 confirmed active exploitation against a limited set of customers. The combined report highlighted that both vulnerabilities were being actively targeted and underscored the urgency of applying the recommended patches and network‑level mitigations.

## Timeline

### 2026-08-01: Ruflo AI Platform and Check Point SmartConsole Hit by Critical Zero-Day Flaws

Critical zero‑day flaws were disclosed in Ruflo’s AI platform (remote code execution and AI memory poisoning) and Check Point’s SmartConsole (authentication bypass granting admin access).

2 sources. https://clstr.news/cluster/ruflo-ai-platform-and-check-point-smartconsole-hit-by-critical-zero-day-flaws

### 2026-07-29: Ruflo AI Orchestration Platform Exposes Critical CVE-2026-59726 Flaw

A critical CVE‑2026‑59726 flaw in Ruflo’s MCP Bridge (CVSS 10.0) lets unauthenticated attackers execute commands, steal AI provider keys and tamper with persistent agent memory; it impacts pre‑3.16.3 Docker‑de​

4 sources. https://clstr.news/cluster/ruflo-ai-orchestration-platform-faces-critical-remote-code-execution-flaw

---
Cite as: Critical zero‑day flaws in Ruflo AI platform. CLSTR, https://clstr.news/situations/critical-zeroday-flaws-in-ruflo-ai-platform
