Msdynamicsworld Microsoft Updates Dynamics 365 Bug Bounty Program
Article Content
- •Microsoft's updated bug bounty program offers rewards from $1,250 to $60,000.
- •High-Impact Scenario Awards can double bounty amounts for critical vulnerabilities.
- •The program covers both Microsoft products and third-party components.
On September 17, 2026, Microsoft announced updates to its Dynamics 365 and Power Platform bug bounty program, offering bounty awards ranging from $1,250 to $60,000 for identifying security vulnerabilities. The program now includes a category for High-Impact Scenario Awards, which can provide up to 100% multipliers for critical vulnerabilities. Researchers are encouraged to report vulnerabilities that are classified as Critical or Important severity and reproducible on the latest versions of the products. The updated bounty program reflects a growing focus on cybersecurity as attack surfaces expand, particularly with the rise of generative AI tools. The program covers not only Microsoft products but also third-party and open-source components. Specific vulnerabilities eligible for bounties include cross-tenant vulnerabilities and privilege escalation scenarios. Microsoft has been enhancing its bug bounty program since its launch in 2019, with significant updates in 2022 and 2024. The company encourages researchers to utilize its MSRC Research Portal for submissions.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Continue Reading
Microsoft September 2026 Patch Tuesday: Record 974 Vulnerabilities Addressed On September 8, 2026, Microsoft released a record-breaking 974 patches for vulnerabilities across its products, including two actively exploited zero-day vulnerabilities: CVE-2026-81963 and CVE-2026-85880. These vulnerabilities allow local attackers to escalate privileges to SYSTEM level, posing significant risks to…
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…