I think legal's involvement is perfectly normal. Part of damage control consists of figuring out the legal ramifications of the product/service having technical vulnerabilities. Especially if those vulnerabilities leak customer data.
What isn't cool is legal deciding to go after the party disclosing the vulnerability.