SECURITY·중요도 10·2026. 07. 29.·The Hacker News

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

── KO ──────────────────

Ruflo의 중대한 보안 취약점이 발견되어 원격 코드 실행이 가능해졌다.

사이버 보안 연구자들이 Ruflo에서 심각한 보안 취약점을 발견했습니다. 이 취약점은 인증되지 않은 공격자가 원격으로 코드 실행을 할 수 있도록 허용합니다. CVE-2026-59726로 추적되는 이 취약점은 Ruflo의 모든 버전에 영향을 미치며, 최대 CVSS 점수인 10.0을 기록했습니다.


── EN ──────────────────

A critical security flaw in Ruflo allows unauthenticated remote code execution.

Cybersecurity researchers have identified a critical security flaw in Ruflo that allows unauthenticated attackers to execute commands remotely. This vulnerability is tracked as CVE-2026-59726 with a maximum CVSS score of 10.0, affecting all versions prior to 3.16.3. This vulnerability is codenamed RufRoot by Noma Security.

원문 보기 →목록으로