Find notable cyber news and cases, enriched with sources, timelines, and signals.

Ruflo maintainer Reuven Cohen security patch release for CVE-2026-59726

Security Patch Release
First reported
Last updated
Happening score
H score 45
1 unique sources, 1 articles

Summary

Hide ▲

Ruflo pushed a fix for CVE-2026-59726, closing a maximum-severity unauthenticated RCE issue in the project's default MCP bridge. The patch landed within 24 hours of June 30, 2026 disclosure and raised the default posture for version 3.16.3 and later. The release matters because exposed deployments could otherwise let a network attacker invoke terminal_execute, steal provider keys, and tamper with stored AI memory.

Related Happenings

Ruflo exposed-instance remediation guidance

Advisory/Mitigation
H score57 First: 29.07.2026 18:39 Last: 29.07.2026 18:39 Sources 1

How related: Operators running an exposed instance are recommended to immediately close firewall ports 3001 and 27017, rotate all LLM API keys, audit the AgentDB pattern store for injected agentdb_pattern-store entries, and check MongoDB for signs of tampering.

About this happening: Operators running exposed Ruflo instances are being told to close ports 3001 and 27017, rotate all LLM API keys, and inspect for tampering after disclosure of CV...

Hugging Face diffusers 0.38.0 security patch release

Security Patch Release
H score14 First: 28.07.2026 18:15 Last: 28.07.2026 18:15 Sources 1

About this happening: Hugging Face released diffusers 0.38.0 on May 1, moving security checks to dynamic-module loading and closing the identified bypass variants.

Linux kernel upstream security patch release for CVE-2026-53264

Security Patch Release
H score32 First: 28.07.2026 11:04 Last: 28.07.2026 11:04 Sources 1

About this happening: Linux kernel maintainers have backported CVE-2026-53264 fixes across stable branches, closing a local privilege-escalation path that can turn a local user into root on...

Linux kernel stable maintainers security patch release for CVE-2026-53359

Security Patch Release
H score41 First: 06.07.2026 20:37 Last: 06.07.2026 20:37 Sources 1

About this happening: The Linux kernel shipped stable fixes for CVE-2026-53359, closing a KVM use-after-free on x86 hosts with nested virtualization. The fix reached 7.1.3, 6.18.3...

LiteLLM v1.83.14-stable security fix release (multiple vulnerabilities)

Security Patch Release
H score42 First: 15.06.2026 19:39 Last: 15.06.2026 19:39 Sources 1

About this happening: BerriAI shipped LiteLLM v1.83.14-stable to close a three-CVE chain that could let a low-privilege proxy user reach full admin and run code on the server. The u...

Timeline

  1. 29.07.2026 18:39 1 articles · 1h ago

    Noma Security flags CVE-2026-59726 in Ruflo's default MCP bridge

    Initial Disclosure

    Noma Security identified CVE-2026-59726, a CVSS 10.0 flaw in Ruflo's default MCP bridge before version 3.16.3 that exposed POST /mcp without authentication and allowed an unauthenticated network attacker to invoke terminal_execute for remote code execution, provider API-key theft, conversation harvesting, and AI memory poisoning.

    Show sources
  2. 29.07.2026 18:39 2 articles · 1h ago

    Reuven Cohen pushes a fix for Ruflo's unauthenticated MCP bridge exposure

    Mitigation Patch Update

    Ruflo maintainer Reuven Cohen pushed a fix within 24 hours of the June 30, 2026 responsible disclosure, addressing the unauthenticated MCP bridge exposure in versions before 3.16.3.

    Show sources