Ruflo fixed a CVSS 10.0 flaw that exposed its MCP bridge without any authentication, putting AI provider keys, stored chats and persistent agent memory at risk.
An AI-driven threat actor called JADEPUFFER built ransomware that hunts AI model files specifically, entering through a known Langflow RCE and pivoting via an exposed Docker socket.
The critical libssh2 CVE-2026-55200 flaw inverts SSH security: the remote server attacks the connecting client, no credentials needed. A public PoC is out and the official patched release has not shipped.