GUARDED 8 min read 30 Jul 2026

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory Leads Today's Security Review

Executive assessment Today's brief leads with Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory. All 15 selected findings retain their own technical scope, action, observed status, and evidence limits.

Key findings
01
Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory
CRITICAL
Cybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, that could result in unauthenticated remote code execution.
02
Still active: Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
CRITICAL
First reported 2026-07-29; ongoing coverage. A maximum-severity security flaw impacting on-premises versions of Arista VeloCloud Orchestrator (VCO) has come under active exploitation in the wild.
03
Still active: CVE-2026-62325: goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-…
CRITICAL
First reported 2026-07-29; ongoing coverage. goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884). CVE coverage: CVE-2026-62325.
04
ZDI-26-501: WatchGuard FireWare OS sigd compstartcb Directory Traversal Arbitrary File Creation Vulnerability…
HIGH
This vulnerability allows remote attackers to create arbitrary files on affected installations of WatchGuard FireWare OS. Authentication is required to exploit this vulnerability. The assigned identifier is CVE-2026-13054.
05
ZDI-26-500: WatchGuard FireWare OS networkd networkwirelesskickoffuser_cb Stack-based Buffer Overflow Remote Code Execution Vulnerability…
HIGH
This vulnerability allows remote attackers to execute arbitrary code on affected installations of WatchGuard FireWare OS. Authentication is required to exploit this vulnerability. The assigned identifier is CVE-2026-13050.
06
ZDI-26-494: Apple macOS USD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability…
HIGH
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Apple macOS. Interaction with the USD library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The assigned identifier is CVE-2026-43729.
07
ZDI-26-493: Apple macOS USD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability…
HIGH
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Apple macOS. Interaction with the USD library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The assigned identifier is CVE-2026-43733.
08
ZDI-26-492: Apple macOS ImageIO Numeric Truncation Remote Code Execution Vulnerability
HIGH
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Apple macOS. Interaction with the ImageIO library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The assigned identifier is CVE-2026-43780.
09
ZDI-26-491: Apple macOS CoreAudio Out-Of-Bounds Write Remote Code Execution Vulnerability
HIGH
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Apple macOS. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The assigned identifier is CVE-2026-43673.
10
ZDI-26-499: WatchGuard FireWare OS cli Token Parser Stack-based Buffer Overflow Remote Code Execution Vulnerability…
HIGH
This vulnerability allows remote attackers to execute arbitrary code on affected installations of WatchGuard FireWare OS. Authentication is required to exploit this vulnerability. The assigned identifier is CVE-2026-13053.
11
CVE-2024-4944: A local privilege escalation vlnerability in the WatchGuard Mobile VPN with SSL
HIGH
A local privilege escalation vlnerability in the WatchGuard Mobile VPN with SSL client on Windows enables a local user to execute arbitrary commands with elevated privileged. CVE coverage: CVE-2024-4944.
12
ZDI-26-482: Progress Software Kemp LoadMaster enablexroot Use of Hard-Coded Cryptographic Key Privilege Escalation Vulnerability…
HIGH
This vulnerability allows remote attackers to escalate privileges on affected installations of Progress Software Kemp LoadMaster. Authentication is required to exploit this vulnerability. The assigned identifier is CVE-2026-59689.
13
ZDI-26-481: Progress Software Kemp LoadMaster access Missing Authorization Privilege Escalation Vulnerability…
HIGH
This vulnerability allows remote attackers to escalate privileges on affected installations of Progress Software Kemp LoadMaster. Authentication is required to exploit this vulnerability. The assigned identifier is CVE-2026-59690.
14
GHSA-wchh-9x6h-7f6p: olm dependency deprecation: CVE-2022-39255 and CVE-2024-45193
HIGH
olm dependency deprecation: CVE-2022-39255 and CVE-2024-45193. CVE coverage: CVE-2022-39255, CVE-2024-45193.
15
Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser
MEDIUM
Nebula Security says a patched Firefox JIT flaw could be triggered by simply visiting a malicious webpage and was also used to compromise Tor Browser. Tracked as CVE-2026-10702, the bug provides arbitrary code execution inside the browser's renderer process.

Executive assessment

Today's brief leads with Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory. All 15 selected findings retain their own technical scope, action, observed status, and evidence limits.

Finding 01 — Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

What changed: Cybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, that could result in unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-59726 (CVSS score: 10.0), impacts all versions of the project before version 3.16.3.

Technical evidence: CVE-2026-59726; CVSS v3.1 10; weakness ['CWE-78', 'CWE-306', 'CWE-942']; technical confidence Medium.

Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-59726 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: thehackernews.com](<https://thehackernews.com/2026/07/ruflo-mcp-flaw-lets-unauthenticated.html>)

Finding 02 — Still active: Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw

Coverage status: First reported 2026-07-29; ongoing coverage.

What changed: A maximum-severity security flaw impacting on-premises versions of Arista VeloCloud Orchestrator (VCO) has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-16812 (CVSS score: 10.0), is a case of operating system command injection that could pave the way for arbitrary code execution.

Technical evidence: CVE-2026-16812; CVSS v3.1 10; weakness ['CWE-78']; technical confidence High.

Why it matters: Reported active exploitation elevates this above routine patching: validate exposure immediately, remediate, and assess for prior compromise.

Observed status: Observed in-the-wild exploitation is confirmed.

Action: Map CVE-2026-16812 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: fixed version or patch state unknown

affected product not structured

[Evidence source: thehackernews.com](<https://thehackernews.com/2026/07/attackers-exploit-arista-velocloud.html>)

Finding 03 — Still active: CVE-2026-62325: goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-…

Coverage status: First reported 2026-07-29; ongoing coverage.

What changed: goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884). CVE coverage: CVE-2026-62325.

Technical evidence: CVE-2026-62325; CVSS v3.1 9.1; weakness ['CWE-306']; technical confidence High.

Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-62325 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: github.com](<https://github.com/advisories/GHSA-rjrw-mjq6-hpmm>)

Finding 04 — ZDI-26-501: WatchGuard FireWare OS sigd compstartcb Directory Traversal Arbitrary File Creation Vulnerability…

What changed: This vulnerability allows remote attackers to create arbitrary files on affected installations of WatchGuard FireWare OS. Authentication is required to exploit this vulnerability.

Technical evidence: CVE-2026-13054; CVSS v4.0 8.6; weakness ['CWE-22']; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-13054 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

[Evidence source: www.zerodayinitiative.com](<http://www.zerodayinitiative.com/advisories/ZDI-26-501/>)

Finding 05 — ZDI-26-500: WatchGuard FireWare OS networkd networkwirelesskickoffuser_cb Stack-based Buffer Overflow Remote Code Execution Vulnerability…

What changed: This vulnerability allows remote attackers to execute arbitrary code on affected installations of WatchGuard FireWare OS. Authentication is required to exploit this vulnerability.

Technical evidence: CVE-2026-13050; CVSS v4.0 8.6; weakness ['CWE-787']; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-13050 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

[Evidence source: www.zerodayinitiative.com](<http://www.zerodayinitiative.com/advisories/ZDI-26-500/>)

Finding 06 — ZDI-26-494: Apple macOS USD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability…

What changed: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Apple macOS. Interaction with the USD library is required to exploit this vulnerability but attack vectors may vary depending on the implementation.

Technical evidence: CVE-2026-43729; CVSS v3.1 7.8; weakness ['CWE-119']; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-43729 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

[Evidence source: www.zerodayinitiative.com](<http://www.zerodayinitiative.com/advisories/ZDI-26-494/>)

Finding 07 — ZDI-26-493: Apple macOS USD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability…

What changed: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Apple macOS. Interaction with the USD library is required to exploit this vulnerability but attack vectors may vary depending on the implementation.

Technical evidence: CVE-2026-43733; CVSS v3.1 7.8; weakness ['CWE-119']; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-43733 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

[Evidence source: www.zerodayinitiative.com](<http://www.zerodayinitiative.com/advisories/ZDI-26-493/>)

Finding 08 — ZDI-26-492: Apple macOS ImageIO Numeric Truncation Remote Code Execution Vulnerability

What changed: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Apple macOS. Interaction with the ImageIO library is required to exploit this vulnerability but attack vectors may vary depending on the implementation.

Technical evidence: CVE-2026-43780; CVSS v3.1 7.8; weakness ['CWE-190']; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-43780 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

[Evidence source: www.zerodayinitiative.com](<http://www.zerodayinitiative.com/advisories/ZDI-26-492/>)

Finding 09 — ZDI-26-491: Apple macOS CoreAudio Out-Of-Bounds Write Remote Code Execution Vulnerability

What changed: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Apple macOS. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.

Technical evidence: CVE-2026-43673; CVSS v3.1 7.8; weakness ['CWE-119']; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-43673 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

[Evidence source: www.zerodayinitiative.com](<http://www.zerodayinitiative.com/advisories/ZDI-26-491/>)

Finding 10 — ZDI-26-499: WatchGuard FireWare OS cli Token Parser Stack-based Buffer Overflow Remote Code Execution Vulnerability…

What changed: This vulnerability allows remote attackers to execute arbitrary code on affected installations of WatchGuard FireWare OS. Authentication is required to exploit this vulnerability.

Technical evidence: CVE-2026-13053; CVSS v4.0 8.6; weakness ['CWE-787']; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-13053 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

[Evidence source: www.zerodayinitiative.com](<http://www.zerodayinitiative.com/advisories/ZDI-26-499/>)

Finding 11 — CVE-2024-4944: A local privilege escalation vlnerability in the WatchGuard Mobile VPN with SSL

What changed: A local privilege escalation vlnerability in the WatchGuard Mobile VPN with SSL client on Windows enables a local user to execute arbitrary commands with elevated privileged. CVE coverage: CVE-2024-4944.

Technical evidence: CVE-2024-4944; CVSS v4.0 8.5; weakness ['CWE-77']; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2024-4944 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

[Evidence source: nvd.nist.gov](<https://nvd.nist.gov/vuln/detail/CVE-2024-4944>)

Finding 12 — ZDI-26-482: Progress Software Kemp LoadMaster enablexroot Use of Hard-Coded Cryptographic Key Privilege Escalation Vulnerability…

What changed: This vulnerability allows remote attackers to escalate privileges on affected installations of Progress Software Kemp LoadMaster. Authentication is required to exploit this vulnerability.

Technical evidence: CVE-2026-59689; CVSS v3.1 8; weakness ['CWE-863']; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-59689 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: www.zerodayinitiative.com](<http://www.zerodayinitiative.com/advisories/ZDI-26-482/>)

Finding 13 — ZDI-26-481: Progress Software Kemp LoadMaster access Missing Authorization Privilege Escalation Vulnerability…

What changed: This vulnerability allows remote attackers to escalate privileges on affected installations of Progress Software Kemp LoadMaster. Authentication is required to exploit this vulnerability.

Technical evidence: CVE-2026-59690; CVSS v3.1 8; weakness ['CWE-862']; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-59690 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: www.zerodayinitiative.com](<http://www.zerodayinitiative.com/advisories/ZDI-26-481/>)

Finding 14 — GHSA-wchh-9x6h-7f6p: olm dependency deprecation: CVE-2022-39255 and CVE-2024-45193

What changed: olm dependency deprecation: CVE-2022-39255 and CVE-2024-45193. CVE coverage: CVE-2022-39255, CVE-2024-45193.

Technical evidence: CVE-2022-39255; CVSS v3.1 8.6; weakness ['CWE-322', 'CWE-287']; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2022-39255 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: github.com](<https://github.com/advisories/GHSA-wchh-9x6h-7f6p>)

Finding 15 — Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser

What changed: Nebula Security says a patched Firefox JIT flaw could be triggered by simply visiting a malicious webpage and was also used to compromise Tor Browser. Tracked as CVE-2026-10702, the bug provides arbitrary code execution inside the browser's renderer process.

Technical evidence: CVE-2026-10702; CVSS v3.1 4.3; weakness ['CWE-843']; technical confidence High.

Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-10702 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: thehackernews.com](<https://thehackernews.com/2026/07/researchers-show-single-malicious.html>)

cve-2022-39255cve-2024-4944cve-2026-10702cve-2026-13050cve-2026-13053cve-2026-13054cve-2026-16812cve-2026-43673cve-2026-43729cve-2026-43733

Act on this brief

Map detection coverage gaps for the techniques above, or generate Sigma rules from the named CVEs.