Vulnerabilities

Microsoft Bug Bounty Program: $20 Million Paid to 500 Researchers

The biggest single reward paid out by Microsoft between July 1, 2025, and June 30, 2026, was $200,000.

Microsoft security

Microsoft announced on Monday that over the past year it has paid out more than $20 million through its bug bounty programs.

Between July 1, 2025, and June 30, 2026, the company received vulnerability reports through its 15 bug bounty programs from researchers across 64 countries.

Microsoft said it received 2,531 eligible reports, and 562 researchers have been awarded a total of over $20 million, with the largest single payout reaching $200,000.

[ Read: Will AI Kill the Bug Bounty Industry? ]

The total amount includes $2.3 million given to participants at the Zero Day Quest hacking contest. In addition, $800,000 was paid out through new initiatives, such as those targeting vulnerabilities in third-party and open source code

Microsoft noted that it saw a significant increase in submission volume during the second half of the year, which it attributed to “both strong engagement from the research community and the growing use of AI to support security research”.

Advertisement. Scroll to continue reading.

Microsoft paid out roughly $17 million in 2024 and 2025, and approximately $13 million every year between 2020 and 2023.

While the latest numbers show that Microsoft’s bug bounty programs are increasingly successful, not all researchers are happy with the company’s handling of vulnerability reports.

A researcher who uses the online moniker Chaotic Eclipse and Nightmare Eclipse has released the details of several zero-days without giving Microsoft the chance to patch them. Some of the flaws ended up being exploited in the wild

Chaotic Eclipse has voiced strong dissatisfaction with Microsoft, alleging that the company mishandled vulnerability reports, ignored communications, withheld bounty payments, deleted the researcher’s reporting account, and breached a prior agreement.

Related: Google Paid Out $17 Million in Bug Bounty Rewards in 2025

Related: Apple Bug Bounty Update: Top Payout $2 Million, $35 Million Paid to Date

Related: Meta Paid Out $4 Million via Bug Bounty Program in 2025

Related Content

Vulnerabilities

CISA is urging government agencies to immediately patch the Citrix NetScaler vulnerability tracked as CVE-2026-8452.

Vulnerabilities

Adobe and Nvidia each published several advisories, including ones that address critical vulnerabilities in their products.

Vulnerabilities

Most of the flaws were discovered by Google using AI, but researchers are still discovering high-value Chrome vulnerabilities.

Vulnerabilities

CVE-2026-60004 is a remote code execution vulnerability patched by Gitea developers in late July with the release of version 1.27.1.

Vulnerabilities

CVE-2026-61979 and CVE-2026-15981 are authentication bypass vulnerabilities affecting the MiniOrange SAML 2.0 SSO plugin.

Vulnerabilities

The vulnerability is tracked as CVE-2026-21962 and it has been widely exploited by threat actors against WebLogic servers.

Vulnerabilities

More than 200 vulnerabilities have been patched to date this year, compared to only 16 in 2025 and 22 in 2024. 

Vulnerabilities

The type confusion bug can lead to V8 sandbox escape and control-flow hijacking of the host process.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version