Ruflo maintainer Reuven Cohen security patch release for CVE-2026-59726
Security Patch Release
Summary
Hide ▲
Show ▼
Ruflo pushed a fix for CVE-2026-59726, closing a maximum-severity unauthenticated RCE issue in the project's default MCP bridge. The patch landed within 24 hours of June 30, 2026 disclosure and raised the default posture for version 3.16.3 and later. The release matters because exposed deployments could otherwise let a network attacker invoke terminal_execute, steal provider keys, and tamper with stored AI memory.
Related Happenings
Ruflo exposed-instance remediation guidance
Advisory/Mitigation
H score57
First: 29.07.2026 18:39
Last: 29.07.2026 18:39
Sources 1
How related:
Operators running an exposed instance are recommended to immediately close firewall ports 3001 and 27017, rotate all LLM API keys, audit the AgentDB pattern store for injected agentdb_pattern-store entries, and check MongoDB for signs of tampering.
About this happening:
Operators running exposed Ruflo instances are being told to close ports 3001 and 27017, rotate all LLM API keys, and inspect for tampering after disclosure of CV...
Ruflo exposed-instance remediation guidance
Advisory/MitigationHow related: Operators running an exposed instance are recommended to immediately close firewall ports 3001 and 27017, rotate all LLM API keys, audit the AgentDB pattern store for injected agentdb_pattern-store entries, and check MongoDB for signs of tampering.
About this happening: Operators running exposed Ruflo instances are being told to close ports 3001 and 27017, rotate all LLM API keys, and inspect for tampering after disclosure of CV...
Hugging Face diffusers 0.38.0 security patch release
Security Patch Release
H score14
First: 28.07.2026 18:15
Last: 28.07.2026 18:15
Sources 1
About this happening:
Hugging Face released diffusers 0.38.0 on May 1, moving security checks to dynamic-module loading and closing the identified bypass variants.
Hugging Face diffusers 0.38.0 security patch release
Security Patch ReleaseAbout this happening: Hugging Face released diffusers 0.38.0 on May 1, moving security checks to dynamic-module loading and closing the identified bypass variants.
Linux kernel upstream security patch release for CVE-2026-53264
Security Patch Release
H score32
First: 28.07.2026 11:04
Last: 28.07.2026 11:04
Sources 1
About this happening:
Linux kernel maintainers have backported CVE-2026-53264 fixes across stable branches, closing a local privilege-escalation path that can turn a local user into root on...
Linux kernel upstream security patch release for CVE-2026-53264
Security Patch ReleaseAbout this happening: Linux kernel maintainers have backported CVE-2026-53264 fixes across stable branches, closing a local privilege-escalation path that can turn a local user into root on...
Linux kernel stable maintainers security patch release for CVE-2026-53359
Security Patch Release
H score41
First: 06.07.2026 20:37
Last: 06.07.2026 20:37
Sources 1
About this happening:
The Linux kernel shipped stable fixes for CVE-2026-53359, closing a KVM use-after-free on x86 hosts with nested virtualization. The fix reached 7.1.3, 6.18.3...
Linux kernel stable maintainers security patch release for CVE-2026-53359
Security Patch ReleaseAbout this happening: The Linux kernel shipped stable fixes for CVE-2026-53359, closing a KVM use-after-free on x86 hosts with nested virtualization. The fix reached 7.1.3, 6.18.3...
LiteLLM v1.83.14-stable security fix release (multiple vulnerabilities)
Security Patch Release
H score42
First: 15.06.2026 19:39
Last: 15.06.2026 19:39
Sources 1
About this happening:
BerriAI shipped LiteLLM v1.83.14-stable to close a three-CVE chain that could let a low-privilege proxy user reach full admin and run code on the server. The u...
LiteLLM v1.83.14-stable security fix release (multiple vulnerabilities)
Security Patch ReleaseAbout this happening: BerriAI shipped LiteLLM v1.83.14-stable to close a three-CVE chain that could let a low-privilege proxy user reach full admin and run code on the server. The u...
Timeline
-
29.07.2026 18:39 1 articles · 1h ago
Noma Security flags CVE-2026-59726 in Ruflo's default MCP bridge
Initial DisclosureNoma Security identified CVE-2026-59726, a CVSS 10.0 flaw in Ruflo's default MCP bridge before version 3.16.3 that exposed POST /mcp without authentication and allowed an unauthenticated network attacker to invoke terminal_execute for remote code execution, provider API-key theft, conversation harvesting, and AI memory poisoning.
Show sources
- Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory — thehackernews.com — 29.07.2026 18:39
-
29.07.2026 18:39 2 articles · 1h ago
Reuven Cohen pushes a fix for Ruflo's unauthenticated MCP bridge exposure
Mitigation Patch UpdateRuflo maintainer Reuven Cohen pushed a fix within 24 hours of the June 30, 2026 responsible disclosure, addressing the unauthenticated MCP bridge exposure in versions before 3.16.3.
Show sources
- Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory — thehackernews.com — 29.07.2026 18:39
- Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory — thehackernews.com — 29.07.2026 18:39