A critical vulnerability, tracked as CVE-2026-59726, has been discovered in the Ruflo AI agent platform, allowing unauthenticated attackers to hijack enterprise AI environments by exploiting an exposed Model Context Protocol bridge. This flaw, dubbed RufRoot, affects Ruflo versions prior to 3.16.3 and carries a maximum CVSS score of 10.0, indicating a severe risk. Attackers can execute arbitrary code, steal large language model API keys, and access user data, giving them significant control over the compromised system. The vulnerability is particularly concerning as it can be exploited without authentication, making it easily accessible to malicious actors1. As a result, practitioners should prioritize patching Ruflo versions to 3.16.3 or later to mitigate the risk of exploitation, especially given the expanded active attack surface posed by this disclosure.