{
 "description": "Evidence-bound MITRE ATT&CK techniques observed in ctipilot.ch entries referencing CVE-2026-59726 (RufRoot) \u2014 Ruflo's MCP bridge took unauthenticated tool calls on all interfaces, and the memory it poisons is not cleaned up by the patch (CVSS 10.0). Score = number of published entries mapping the technique. Pinned dataset: ATT&CK v19.1.",
 "domain": "enterprise-attack",
 "gradient": {
  "colors": [
   "#ffe766",
   "#ff6666"
  ],
  "maxValue": 1,
  "minValue": 0
 },
 "hideDisabled": false,
 "layout": {
  "layout": "side",
  "showID": true,
  "showName": true
 },
 "legendItems": [],
 "metadata": [
  {
   "name": "source",
   "value": "ctipilot.ch"
  },
  {
   "name": "entity",
   "value": "CVE-2026-59726"
  },
  {
   "name": "attack_version",
   "value": "19.1"
  }
 ],
 "name": "CVE-2026-59726 (RufRoot) \u2014 Ruflo's MCP bridge took unauthenticated tool calls on all interfaces, and the memory it poisons is not cleaned up by the patch (CVSS 10.0) \u2014 ctipilot.ch coverage",
 "sorting": 3,
 "techniques": [
  {
   "comment": "entries: 2026-07-30/rufroot-cve-2026-59726-ruflo-mcp-bridge-unauth-rce",
   "score": 1,
   "techniqueID": "T1059.004"
  },
  {
   "comment": "entries: 2026-07-30/rufroot-cve-2026-59726-ruflo-mcp-bridge-unauth-rce",
   "score": 1,
   "techniqueID": "T1190"
  },
  {
   "comment": "entries: 2026-07-30/rufroot-cve-2026-59726-ruflo-mcp-bridge-unauth-rce",
   "score": 1,
   "techniqueID": "T1552.001"
  },
  {
   "comment": "entries: 2026-07-30/rufroot-cve-2026-59726-ruflo-mcp-bridge-unauth-rce",
   "score": 1,
   "techniqueID": "T1565.001"
  },
  {
   "showSubtechniques": true,
   "techniqueID": "T1059"
  },
  {
   "showSubtechniques": true,
   "techniqueID": "T1552"
  },
  {
   "showSubtechniques": true,
   "techniqueID": "T1565"
  }
 ],
 "versions": {
  "attack": "19",
  "layer": "4.5",
  "navigator": "5.1.0"
 }
}