Skip to content

Microsoft Bounty Program year in review More than $20 million awarded in our biggest year yet

Microsoft • August 3, 2026

This year, the Microsoft Bounty Program awarded more than $20 million to 562 security researchers , the highest total payout and the largest number of researchers recognized in the program's history. Researchers from 64 countries contributed findings that helped protect customers worldwide.

MSRC is proud to recognize the global community of security researchers who help protect customers through coordinated vulnerability disclosure. Researchers partnered with us to identify and report vulnerabilities across Microsoft's products and services, helping strengthen security for customers worldwide. Last year, the program distributed $17 million to 344 researchers from 59 countries, setting what was then a program record.

Security is a team sport. Every vulnerability reported through our bounty programs represents an opportunity to address risk before it can be exploited against customers. The work of the research community plays a critical role in helping Microsoft stay ahead of emerging threats while strengthening the security of cloud services, AI systems, enterprise platforms, and consumer technologies.

This year brought significant growth across Microsoft's vulnerability awards programs, helping us recognize more researchers and more impactful security findings. We also saw a notable increase in submission volume during the second half of the year, reflecting both strong engagement from the research community and the growing use of AI to support security research.

This year, Microsoft Zero Day Quest brought together security researchers from 20 countries at Microsoft’s Redmond campus to collaborate directly with security and engineering teams. Through the research challenge and live hacking event, participants focused on high-priority security scenarios across Microsoft’s cloud and AI platforms, submitting nearly 700 vulnerability reports and earning $2.3 million in awards.

Beyond expanding opportunities through Zero Day Quest, Microsoft continued to evolve its vulnerability rewards portfolio to recognize impactful research across a broader range of technologies.

Last year, we expanded our vulnerability awards portfolio to recognize impactful research beyond traditional bounty scopes, including eligible open-source software , third-party components , and Microsoft cloud services . Since then, we have received more than 300 additional reports and awarded more than $800,000 for vulnerabilities that would not previously have qualified for bounty awards.

This year’s record-breaking results, including more than $20 million in awards and recognition for 562 researchers, reflect the impact of a strong partnership between Microsoft and the global security research community.

Whether participating through a traditional bounty submission, collaborating through coordinated vulnerability disclosure, or joining initiatives such as Zero Day Quest, researchers continue to play a vital role in protecting customers around the world.

To every researcher who submitted a report, participated in a challenge, shared expertise, or partnered with us over the past year: thank you.

Together, we're making Microsoft's products and services more secure for billions of people worldwide.

Extracted Entities

Campaigns (1)