Ruflo RufRoot MCP flaw opens AI-agent bridge
Ruflo CVE-2026-59726 exposed an unauthenticated MCP bridge that could let outsiders run tools, steal provider API keys, and poison AI memory; upgrade to 3.16.3, restrict network access, and audit keys and memory stores.