Informa TechTarget | SearchSecurity Cybersecurity Dive InformationWeek Channel Dive Explore our brands Dark Reading Resource Library Black Hat News Omdia Cybersecurity Advertise NEWSLETTER SIGN-UP Cybersecurity Topics World The Edge DR Technology Events Resources CYBER RISK THREAT INTELLIGENCE VULNERABILITIES & THREATS CYBERSECURITY ANALYTICS NEWS Patch-Resistant 'RufRoot' Flaw Can Unleash Malicious AI Agent Swarms The vulnerability in the AI hosting platform Ruflo allows an unauthenticated attacker to take over the system and corrupt memory, so bad behavior can persist after patching. Elizabeth Montalbano,Contributing Writer July 29, 2026 4 Min Read SOURCE: BRAIN LIGHT VIA ALAMY STOCK PHOTO A maximum-severity vulnerability in the open source AI agent platform Ruflo puts enterprise AI deployments at risk by letting attackers conduct various malicious activities from inside the orchestration framework. The flaw also can leave agents behaviorally compromised even after it's been patched. Researchers at Noma Security's Noma Labs discovered the flaw, tracked as CVE-2026-59726, in Ruflo, formerly called Claude Flow and which hosts AI agent swarms for Codex and Claude Code, they revealed today. The vulnerability, which received the highest CVSS severity score of 10, allowed them to access the platform without logging in at all, according to Noma Labs. "The weakness is a lack of authentication coupled with command execution capabilities, enabling complete control over the container and exposure of sensitive credentials," according to details about the flaw posted on OpenCVE. Specifically, Ruflo's default docker-compose deployment left the MCP bridge POST /mcp and POST /mcp/:group endpoints open without authentication. This allowed an unauthenticated attacker to issue a tools/call to terminal_execute command, obtain a shell inside the bridge container, read stored provider API keys, and modify AgentDB learning-store patterns, according to OpenCVE. Related:Thousands of Data Center Controllers Open to Takeover Memory Tampering Resists Fixes Using their proof of concept (PoC), Noma Labs researchers accessed Ruflo via an unauthenticated model context protocol (MCP) bridge open to the network by default, demonstrating that a single HTTP request was enough to gain full remote code execution inside a Ruflo deployment, they said. Once inside, they could access the API keys Ruflo uses to talk to AI providers and read every user conversation stored on the platform. Given that Ruflo is an AI agent host platform, the flaw could enable attackers to unleash a swarm of AI agents to do whatever they wanted. Perhaps most troubling of all, researchers also found they could tamper with the AI's own memory in ways that would influence its responses to future users long after the attacker had gone, they said. They did this by planting instructions that could steer Ruflo's behavior even after they no longer were inside the system. Noma Labs disclosed the vulnerability to Ruflo maintainers on June 30 and included a working PoC confirmed against a live default deployment. Ruflo responded within 24 hours to release a fix, defaulting the platform to a locked-down configuration with public exposure treated as an explicit opt-in requiring authentication, according to Noma, which independently verified the fix. Related:Attackers Are Learning to Live Off the AI Toolchain Still, merely patching software — the fix for traditional vulnerabilities in enterprise platforms — is no longer a guaranteed solution for a flaw that allows corruption of memory within an AI system, according to Noma Labs. Even with a patch, organization can still be running compromised agents. Indeed, this aspect of the vulnerability represents a new class of risk for enterprises deploying AI agents, experts say. "This is not exploiting software flaws, it is memory poisoning," observes John Gallagher, vice president at OT and IoT cyber hygiene firm Viakoo. Since the cyber threat impacts reasoning, the flaw represents "a critical turning point in cybersecurity, especially OT and IoT systems," he says. Defending Against Novel AI Threats The Ruflo vulnerability discovery comes on the heels of an incident in which OpenAI models autonomously hacked the Hugging Face AI platform during benchmark testing, demonstrating that defenders are facing a new threat paradigm when it comes to protecting systems against the behavior of their own AI systems. While the vulnerability's lack of authentication is not new — and is, in fact, "one of the oldest failure patterns on the Internet" — what is new with AI agent abuse is "what sits behind that door," observes Johan Edholm, security engineer and co-founder of app security testing firm Detectify. Related:When AI Attacks: OpenAI Models Autonomously Hack Hugging Face "An agent platform concentrates everything an attacker wants in one place, with provider API keys, every stored conversation, shell access via its own tools, and a persistent memory the AI trusts," he tells Dark Reading. "In other words, the bug class is old, but the blast radius is new." Indeed, if an attacker can corrupt an AI's reasoning, organizations also need that same capability to use AI to fight AI, says Ram Varadarajan, CEO at cyber detection technology firm Acalvio. This could mean "corrupting the adversarial AI's reasoning before it acts" and employing a bot-on-bot cyber defense, he says. For now, Noma Labs advised, immediate remediation for those affected by CVE-2026-59726 includes treating AI provider credentials as compromised and rotating them, auditing the platform's AI memory for tampering, and rebuilding containers from a clean image. About the Author Elizabeth Montalbano Contributing Writer Elizabeth Montalbano is freelance writer, editor, and journalist with 30 years of professional experience and a master's degree from Arizona State University. Her areas of expertise include enterprise technology, cybersecurity, business, and culture. During her long career, Elizabeth has lived and worked as a full-time journalist in Phoenix, San Francisco, and New York City. She specializes in news coverage and analysis, using her years of experience to look at the current state of cybersecurity with a critical gaze. She currently resides in a village on the southwest coast of Portugal, where in her free time she enjoys surfing, hiking with her dogs, growing plants, and playing and performing as a singer and musician. Want more Dark Reading stories in your Google search results? ADD US NOW More Insights Industry Reports The State of Cloud Security: The Latest Challenges How Organizations Are Managing Incident Response How Enterprises Are Developing Secure Applications Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy Essential News & Insights from Black Hat USA 2025 Access More Research Webinars Experts Explain How to Develop a Framework for Cyber-Fraud Fusion Prevention at Machine Speed: Hunting Beyond Known Detections 0-Day to 10x Discovery: Security at the Speed of Mythos When AI Becomes an Insider: Rethinking Risk in Critical Infrastructure Governing the Agent; Identity Security in the Age of Autonomous AI More Webinars You May Also Like CYBER RISK Claude Mythos Fears Startle Japan's Financial Services Sector by Nate Nelson APR 30, 2026 CYBER RISK How Can CISOs Respond to Ransomware Getting More Violent? by James Doggett JAN 28, 2026 CYBER RISK US Cyber Pros Plead Guilty Over BlackCat Ransomware Activity by Alexander Culafi JAN 05, 2026 CYBER RISK Microsoft Exchange 'Under Imminent Threat,' Act Now by Arielle Waldman NOV 12, 2025 Editor's Choice VULNERABILITIES & THREATS Records Are Made to Be Broken: Patch Tuesday Raises Triage Stakes byJai Vijayan JUL 14, 2026 5 MIN READ PERIMETER 6 GHz Wi-Fi Flaws Could Disrupt Critical Systems byAlexander Culafi JUL 14, 2026 4 MIN READ CYBERSECURITY OPERATIONS 'Yellow Teams' Are Defining the Future of AI Security byNate Nelson JUL 13, 2026 6 MIN READ Want more Dark Reading stories in your Google search results? Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox. SUBSCRIBE AUG 1-6 | MANDALAY BAY, LAS VEGAS USE CODE: DARKREADING & SAVE $200 ON A BRIEFINGS PASS OR $100 ON A BUSINESS PASS The premier cybersecurity event returns. GET YOUR PASS Discover More Black Hat Omdia Working With Us About Us Meet the Editors Advertise Reprints Join Us NEWSLETTER SIGN-UP Follow Us Copyright © 2026 TechTarget, Inc. d/b/a Informa TechTarget. This website is owned and operated by Informa TechTarget, part of a global network that informs, influences and connects the world’s technology buyers and sellers. All copyright resides with them. Informa PLC’s registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. TechTarget, Inc.’s registered office is 275 Grove St. Newton, MA 02466. Home| Cookie Policy| Privacy| Terms of Use Your Privacy Choices