Microsoft Bug Bounty Payouts Reach Record $20 Million


Bounty YIR final
Image credit: Microsoft

Microsoft bug bounty payouts reached a record $20 million during the company’s latest program year as more security researchers submitted vulnerabilities across cloud, AI, and open-source technologies.

The company awarded more than $20 million through its bounty programs between July 1, 2025, and June 30, 2026. A total of 562 researchers received payments, putting the average reward at approximately $35,000 per researcher.

Microsoft distributed around $3 million more than it did during the previous year. However, the average payment per researcher fell from approximately $49,000 to $35,000.

The lower average does not indicate reduced investment in security research. Instead, Microsoft accepted reports from a larger number of researchers and expanded the types of vulnerabilities eligible for rewards.

Zero Day Quest drives more vulnerability reports

Microsoft Zero Day Quest contributed significantly to the record payout total.

Researchers submitted nearly 700 vulnerability reports through the initiative and received $2.3 million in rewards. Participants from 20 countries investigated high-priority security problems affecting Microsoft’s cloud and AI platforms.

The program helped Microsoft attract researchers with different technical backgrounds while directing their attention toward products that could create widespread security risks.

Zero Day Quest also gave researchers a structured way to share findings directly with Microsoft before attackers could exploit the vulnerabilities.

Microsoft expands its bug bounty scope

Microsoft also widened its bounty programs beyond their traditional product and service targets.

Researchers could submit vulnerabilities found in open-source projects, third-party components, and additional Microsoft cloud services. These changes produced more than 300 reports that would not have qualified under the previous rules.

Microsoft paid over $800,000 for vulnerabilities covered by the expanded scope.

The broader eligibility rules reflect how modern Microsoft products depend on external libraries, open-source software, and interconnected cloud services. A weakness in one component can affect several products, even when Microsoft did not create the original code.

AI tools increase bug bounty submissions

Microsoft attributed part of the submission growth to researchers using AI tools during vulnerability discovery.

AI can help researchers analyze code, identify unusual behavior, and test potential security weaknesses more quickly. It can also lower the technical barriers for people entering bug bounty programs.

However, the increase in AI-assisted reports creates a new challenge for security teams. Companies must process more submissions, confirm which reports represent real vulnerabilities, and separate critical findings from low-impact or duplicate reports.

Microsoft has already acknowledged that it can have a hard time keeping up with bugs discovered by Claude Mythos, showing how AI systems can identify flaws faster than developers can investigate and patch them.

The growing number of submissions is changing how technology companies structure their reward programs.

GitHub recently changed its bug bounty payment structure to offer larger rewards and additional benefits for valuable security research.

Microsoft is also strengthening other parts of its software supply chain. The company recently reduced NuGet API key lifetimes to limit the damage caused by stolen or exposed publishing credentials.

More about the topics: microsoft, security

Readers help support Windows Report. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more

User forum

0 messages