Post
CRITICAL

Critical Unauthenticated RCE in Ruflo AI Agent Harness (CVE-2026-59726, CVSS 10.0)

· rce · vulnerability · cve · llm

Researchers disclosed CVE-2026-59726 (CVSS 10.0), a maximum-severity flaw in Ruflo, an open-source agent meta-harness used with Anthropic Claude Code and OpenAI Codex. The bug allows unauthenticated remote code execution and lets an attacker corrupt an agent’s persistent memory, so malicious behavior can survive a patch. Noma Security, which codenamed the flaw RufRoot, says it affects all Ruflo versions before 3.16.3. Dark Reading notes the memory-corruption angle could let an attacker’s foothold propagate across agent swarms built on the affected harness. Organizations running Ruflo should upgrade to 3.16.3 or later and treat any pre-patch agent memory state as untrusted.