All findings

CVE-2026-62912 medium

Aretiq.AI receives a Microsoft Exchange vulnerability credit

MSRC credits E. Cooper with Aretiq.AI on CVE-2026-62912, a Microsoft Exchange Server denial-of-service vulnerability.

Bug class
Remote denial of service
Affected codebase
Microsoft Exchange Server
Credited system
Aretiq.AI
Disclosed
August 11, 2026
Attribution
Self-reported attribution
Severity
medium
Source status: Microsoft confirms the accepted CVE, fix, CVSS 6.5 score, and Aretiq.AI organization credit. Aretiq's own public material establishes the LLM-augmented audit workflow, so the AI-system attribution remains self-reported.

Summary

CVE-2026-62912 can cause Microsoft Exchange Server to stop serving requests. The record is a conservative first entry for Aretiq: the vulnerability is vendor-confirmed, while the exact model and workflow detail comes from the operator.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.