CYBERSECURITYTRACKER
TRACKING7,004 stories in this site build1,474 vulnerability news stories in this site build
Permanent story citation

Microsoft Bug Bounty Program: $20 Million Paid to 500 Researchers

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3774

As cited

Copy frozen at (site build).

industry

Microsoft Bug Bounty Program: $20 Million Paid to 500 Researchers

Microsoft's bug bounty program distributed $20 million to 500 researchers over a 12-month period ending June 30, 2026, with the largest single reward reaching $200,000. The program continues to incentivize external security researchers to identify and report vulnerabilities in Microsoft products and services.

Why it matters: Security researchers evaluating bounty opportunities should note Microsoft's scale of payouts; practitioners should encourage responsible disclosure through bug bounty channels rather than alternative disclosure paths.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

industry

Microsoft Bug Bounty Program: $20 Million Paid to 500 Researchers

Microsoft's bug bounty program distributed $20 million to 500 researchers over a 12-month period ending June 30, 2026, with the largest single reward reaching $200,000. The program continues to incentivize external security researchers to identify and report vulnerabilities in Microsoft products and services.

Why it matters: Security researchers evaluating bounty opportunities should note Microsoft's scale of payouts; practitioners should encourage responsible disclosure through bug bounty channels rather than alternative disclosure paths.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary