AMD Faces Backlash Over Bug Bounty Dispute After Critical Vulnerability
Article Content
Browse articles
- •AMD failed to pay a $10,000 bug bounty for a critical vulnerability discovered by a researcher.
- •The vulnerability, CVE-2026-1234, allows for arbitrary code execution and was patched after 124 days.
- •The incident highlights ongoing issues in the relationship between companies and security researchers.
AMD has been criticized for not paying a $10,000 bug bounty to a researcher who discovered a critical security flaw affecting its processors. The vulnerability, identified as CVE-2026-1234, allows attackers to execute arbitrary code and has been present for 124 days before being patched. The researcher reported the issue in January 2026, but AMD's delay in addressing it has raised concerns about the company's commitment to security. The flaw impacts multiple AMD processor models, potentially affecting millions of users worldwide. The incident has sparked discussions about the ethics of bug bounty programs and the responsibilities of companies to their security researchers.
Ask AI about this cluster
Answers cite the sources they use
Updated 90d ago How this analysis works
Timeline
2026-01-05
Researcher reports vulnerability
A researcher disclosed a critical security flaw in AMD processors, identified as CVE-2026-1234.
Tech.Yahoo2026-06-12
AMD patches the vulnerability
AMD released a patch for CVE-2026-1234, addressing the critical flaw after 124 days.
Tech.Yahoo2026-06-12
Public backlash over bug bounty dispute
AMD faced criticism for not compensating the researcher who reported the vulnerability despite its severity.
Tech.YahooMore articles in this cluster (3)
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…