Vulnerabilities

Microsoft Paid Out $2.3 Million at Zero Day Quest 2026 Hacking Contest

Researchers found more than 80 high-impact cloud and AI vulnerabilities during the event, which had a $5 million prize pool.

Microsoft security

Microsoft has announced the results of its Zero Day Quest 2026 live hacking contest.

The tech giant offered a $5 million prize pool, with $2.3 million awarded to participants across 700 submissions. White hat hackers from over 20 countries took part in the event. 

The company said Zero Day Quest 2026 has helped it learn about 80 high-impact vulnerabilities affecting cloud and AI services.

“Many of the findings showed how weaknesses in identity controls or tenant isolation could allow issues identified within authorized test environments to impact other tenants if combined with execution or network-level vulnerabilities,” Microsoft explained.

It noted that researchers “identified critical paths involving credential exposure, SSRF chains, and cross‑tenant access”.

“These findings reinforce the need for layered defenses and strong isolation boundaries across Microsoft’s cloud and AI services, and underscore the importance of addressing upstream control gaps earlier in the development lifecycle in alignment with Secure Future Initiative priorities,” the company said.

Advertisement. Scroll to continue reading.

At Zero Day Quest 2025, Microsoft paid out $1.6 million to participants. 

In August 2025, Microsoft announced that it had paid out $17 million in bug bounties in the past year, bringing the total payouts since 2018 to more than $92 million.

Related: Infotainment, EV Charger Exploits Earn Hackers $1M at Pwn2Own Automotive 2026

Related: Pwn2Own WhatsApp Hacker Says Exploit Privately Disclosed to Meta

Related: $320,000 Paid Out at Zeroday.Cloud for Open Source Software Exploits

Related Content

ICS/OT

The industrial automation giant has fixed security holes in Logix, CompactLogix, Flex, RSLinx, and FactoryTalk products.

Vulnerabilities

Oracle has released its June 2026 Critical Security Patch Update to fix vulnerabilities in Communications, EBS, Enterprise Manager and other products.

Vulnerabilities

The browser updates address multiple memory safety bugs that could potentially lead to remote code execution.

Vulnerabilities

The flaws allow attackers to execute arbitrary PHP code and gain root privileges on shared hosting servers.

Vulnerabilities

SOCRadar has detected 30,000 compromised Fortinet firewalls that expose networks to hacking. 

Artificial Intelligence

From defending networks to enabling attacks, artificial intelligence is changing every aspect of cybersecurity. Here's what dozens of experts say security leaders need to...

Artificial Intelligence

A group of cybersecurity executives and experts is asking the Trump administration to lift its directive preventing the use of Anthropic’s latest artificial intelligence...

Artificial Intelligence

Anthropic takes Fable 5 and Mythos 5 offline to comply with a directive from the Trump administration to prevent use by foreign nationals.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version