Ruflo's MCP Bridge Exposes 233 Tools Without Auth—CVE-2026-59726
CVE-2026-59726 lets unauthenticated attackers execute shell commands, steal LLM keys, and poison agent memory via Ruflo's exposed /mcp endpoint. Upgrade to 3.16.3 and audit immediately.