Security News Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory TheHackerNews Daniel Bender 29 Jul 2026 Share Ruflo CVE-2026-59726 exposes an unauthenticated MCP bridge that could enable RCE, LLM key theft, conversation access, and AI memory poisoning.