AES Corporation · Vulnerability Disclosure

Aes Vulnerability Disclosure

Vulnerability disclosure

AES Corporation runs a coordinated vulnerability disclosure program on Hackerone.

EnergyPower GenerationRenewable EnergyBattery StorageUtilityClean EnergyFortune 500
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

aes-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-30'
method: probed
source: >-
  Probes of https://www.aes.com/.well-known/security.txt (404),
  https://fluenceenergy.com/.well-known/security.txt (200, expired),
  https://hackerone.com/aes (200) and its ?type=team JSON, plus a DNS/TLS sweep of
  aes.com subdomains, 2026-08-30.
specification: API Commons Vulnerability Disclosure
specificationVersion: '0.1'
provider: AES Corporation
providerId: aes
disclosure_program_published: false
summary: >-
  AES Corporation publishes no vulnerability disclosure policy of its own. There is
  no security.txt on www.aes.com, no /security or /responsible-disclosure page in the
  485-URL sitemap, and the HackerOne entry that surfaces for "AES" is an UNCLAIMED
  external directory listing rather than a program AES operates. Recorded as an
  honest absence: no `Security` pointer is emitted in apis.yml, because emitting one
  would assert a reporting channel that does not exist.
channels:
  - name: HackerOne directory listing
    url: https://hackerone.com/aes
    status: 200
    program_id: 6495
    program_name: The AES Corporation
    handle: aes
    external_program: true
    claimed_by_provider: false
    offers_rewards: false
    policy_text: null
    disclosure_url: null
    disclosure_email: null
    scopes:
      - aes.com
    note: >-
      HackerOne's own JSON reports is_external_program=true and claimed=false with an
      empty policy, empty disclosure_url and empty disclosure_email. An unclaimed
      external listing is a directory stub HackerOne created, not a submission
      channel AES runs, so it is recorded but NOT counted as a published program.
  - name: Fluence Energy security.txt contact
    url: https://fluenceenergy.com/.well-known/security.txt
    status: 200
    contact: mailto:security@fluenceenergy.com
    expired: true
    expires: '2026-01-01T04:59:00.000Z'
    note: >-
      Served by Fluence Energy, Inc. (the AES/Siemens joint venture whose Mosaic and
      Nispera products are this repo's two apis[] entries), not by AES Corporation,
      and stale by eight months against its own Expires field.
probes:
  - url: https://www.aes.com/.well-known/security.txt
    status: 404
  - url: https://www.aes.com/.well-known/api-catalog
    status: 404
  - url: https://fluenceenergy.com/.well-known/security.txt
    status: 200
  - url: https://hackerone.com/aes
    status: 200
observed_exposures:
  - id: dangling-cname-api-aes-com
    severity: informational
    host: api.aes.com
    finding: >-
      api.aes.com is a live CNAME pointing at microgridenergy-api.azurewebsites.net,
      and that Azure App Service name no longer resolves (NXDOMAIN). The record is a
      dangling delegation left behind by a retired AES Microgrid Energy API.
    evidence:
      - 'dig api.aes.com CNAME +short -> microgridenergy-api.azurewebsites.net.'
      - 'dig microgridenergy-api.azurewebsites.net A +short -> (empty); query status NXDOMAIN'
      - 'curl https://api.aes.com/ -> curl (6) Could not resolve host'
    why_it_matters: >-
      Azure App Service hostnames are first-come, first-served. While this CNAME
      stands, whoever registers the microgridenergy-api app name serves content from
      api.aes.com under AES branding and a valid AES-adjacent hostname. Reported here
      as an observed public-DNS fact, not as an exploit; the remedy is for AES to
      delete the CNAME.
    method: probed
    checked: '2026-08-30'
  - id: expired-security-txt-fluence
    severity: low
    host: fluenceenergy.com
    finding: >-
      The one RFC 9116 file across all declared hosts expired 2026-01-01, so a
      researcher following it has no assurance security@fluenceenergy.com is still
      monitored.
    method: probed
    checked: '2026-08-30'
recommendations:
  - Publish /.well-known/security.txt on www.aes.com with a monitored Contact and a Policy URL.
  - Claim or disavow the unclaimed HackerOne listing at https://hackerone.com/aes so researchers know where to report.
  - Remove the dangling api.aes.com CNAME to microgridenergy-api.azurewebsites.net.
  - Refresh the Fluence security.txt Expires field.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/aes-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.