Find notable cyber news and cases, enriched with sources, timelines, and signals.

Ruflo exposed-instance remediation guidance

Advisory/Mitigation
First reported
Last updated
Happening score
H score 57
1 unique sources, 1 articles

Summary

Hide ▲

Operators running exposed Ruflo instances are being told to close ports 3001 and 27017, rotate all LLM API keys, and inspect for tampering after disclosure of CVE-2026-59726. The guidance applies to network-reachable deployments of Ruflo that could be abused for command execution, key theft, and persistent AI-memory poisoning. The recommended response is immediate because exposed instances were described as fully exploitable without authentication.

Related Happenings

Ruflo unauthenticated RCE (CVE-2026-59726)

Vulnerability
H score41 First: 29.07.2026 18:39 Last: 29.07.2026 18:39 Sources 1

How related: The vulnerability, tracked as CVE-2026-59726 (CVSS score: 10.0), impacts all versions of the project before version 3.16.3.

About this happening: CVE-2026-59726 puts Ruflo deployments before 3.16.3 at risk of unauthenticated remote code execution through the default MCP bridge. The flaw exposed 233 too...

Ruflo maintainer Reuven Cohen security patch release for CVE-2026-59726

Security Patch Release
H score45 First: 29.07.2026 18:39 Last: 29.07.2026 18:39 Sources 1

How related: Following responsible disclosure on June 30, 2026, a fix for the vulnerability was pushed by the project's maintainer, Reuven Cohen, within 24 hours.

About this happening: Ruflo pushed a fix for CVE-2026-59726, closing a maximum-severity unauthenticated RCE issue in the project's default MCP bridge. The patch landed within 24 hours...

Popular open-source web-based system administration tool zero-day 2FA-bypass security flaw

Vulnerability
H score5 First: 11.05.2026 16:00 Last: 11.05.2026 16:00 Sources 1

About this happening: An AI-assisted zero-day in a popular open-source web-based system administration tool created a 2FA-bypass risk before the flaw was closed by the vendor. GTIG said...

Nginx UI auth-bypass exploitation wave (CVE-2026-33032)

Exploitation Wave
H score9 First: 16.04.2026 01:35 Last: 16.04.2026 01:35 Sources 1

About this happening: CVE-2026-33032 is now actively exploited, creating immediate risk for publicly exposed Nginx UI instances that rely on the vulnerable /mcp_message endpoint. Intern...

Timeline

  1. 29.07.2026 18:39 1 articles · 1h ago

    Noma Security discloses CVE-2026-59726 in Ruflo

    Initial Disclosure

    On June 30, 2026, security researchers disclosed CVE-2026-59726, a maximum-severity flaw in Ruflo's default MCP bridge that enabled unauthenticated remote code execution and put LLM API keys, user conversations, and AI memory at risk in network-reachable deployments.

    Show sources
  2. 29.07.2026 18:39 2 articles · 1h ago

    Ruflo operators are told to close ports 3001 and 27017

    Mitigation Patch Update

    Following the June 30, 2026 disclosure and the maintainer's fix within 24 hours, operators of exposed Ruflo instances were told to immediately close firewall ports 3001 and 27017, rotate all LLM API keys, audit the AgentDB pattern store for injected agentdb_pattern-store entries, and check MongoDB for signs of tampering.

    Show sources