We research, we share, we empower.
Aretiq AI is an LLM-augmented security research company focused on automated binary and source code auditing.
Research.
In-depth N-day vulnerability analysis — root cause, patch diff, detection, and proof-of-concept.
CVE-2026-15748 — WPMU DEV Forminator Forms Select Field Injection Unrestricted File Upload
1. Overview A vulnerability exists in WPMU DEV’s Forminator Forms plugin for WordPress (600,000+ active installations) that allows …
CVE-2026-61967 — miniOrange OTP Verification Ultimate Member Password Reset Authentication Bypass
1. Overview A vulnerability exists in the miniOrange OTP Verification plugin for WordPress (versions 5.5.1 and earlier) that allows an unauthenticated …
CVE-2026-54995 — Microsoft Windows Reliable Multicast Transport Driver Integer Underflow
1. Overview A vulnerability exists in the Windows Reliable Multicast Transport Driver (rmcast.sys) that implements the Pragmatic General Multicast …
Discoveries.
Original 0-day vulnerabilities discovered by Aretiq AI. We follow responsible disclosure — advisories are published only after vendors have had the opportunity to release patches. Read our Disclosure Policy.
CVE-2026-62801 — Windows PowerShell Security Feature Bypass
Summary A path traversal vulnerability in Windows PowerShell allows an unauthenticated attacker to bypass path validation safeguards over a network. …
CVE-2026-69364 — Windows Print Spooler Components Elevation of Privilege
Summary A race condition in the Windows Print Spooler service leads to a use-after-free that allows an authenticated attacker to escalate privileges …
CVE-2026-62912 — Microsoft Exchange Server Deserialization Denial of Service
Summary A deserialization of untrusted data vulnerability in Microsoft Exchange Server allows any user with a mailbox account to crash the server …
Contact us.
Interested in working with us or learning more? Reach out.