Skip to content
Beveiligingsnieuws

Microsoft Bug Bounty: $20M Paid to 500 Researchers

Microsoft bug bounty

Microsoft says it has paid out more than $20 million through its bug bounty efforts over the past year, rewarding security researchers across the globe. In a period running from July 1, 2025 to June 30, 2026, the company received thousands of vulnerability submissions through its multiple programs.

This update highlights both the scale of Microsoft’s intake and the growing momentum behind its reward process. It also comes with an important caveat: some researchers dispute how certain reports were handled, claiming missed coordination and other issues.

Over $20 million in payouts through multiple programs

According to Microsoft, the company received vulnerability reports through 15 bug bounty programs during the last 12 months. Researchers submitted findings from 64 countries, contributing to a pipeline of eligible vulnerability reports that Microsoft says reached 2,531 eligible submissions.

From those eligible reports, 562 researchers received awards totaling over $20 million. Microsoft also stated that the largest single payout reached $200,000, illustrating that higher-impact findings can translate into substantial rewards.

Key figures: submissions, researchers, and global reach

Looking at the numbers, Microsoft’s bug bounty activity appears to be intensifying. In the reporting window, the company not only attracted submissions from a wide geographic spread, but it also translated those submissions into awards for hundreds of individuals.

Microsoft’s public breakdown emphasizes two metrics that matter to both researchers and defenders: the volume of eligible reports and the count of researchers awarded. Together, these figures suggest that the programs are not only receiving reports, but also recognizing a broad range of vulnerability quality and relevance.

Zero Day Quest rewards included in the total

The total payout figure does not rely on bug bounties alone. Microsoft said that $2.3 million of the overall amount was paid to participants in Zero Day Quest, a hacking contest that includes its own reward structure.

By folding contest payouts into the headline total, Microsoft underscores that its broader vulnerability research ecosystem includes both ongoing program rewards and time-bounded security challenges. For researchers, that can mean additional pathways to incentives beyond standard submission channels.

New initiatives added $800,000 for third-party and open source issues

In addition to the baseline bug bounty programs and the contest component, Microsoft reported $800,000 in payouts through new initiatives. These initiatives focus on vulnerabilities tied to third-party and open source code.

This matters because many real-world security weaknesses do not live solely in a vendor’s own codebase. Instead, they can appear in dependencies, libraries, and components maintained across the open source ecosystem. Incentivizing research in those areas helps defenders reduce risk stemming from upstream issues.

Submission volume rose in the second half of the year

Microsoft noted a meaningful change in its submission patterns: it saw a significant increase in the volume of submissions during the second half of the year. The company attributed this uptick to two main drivers: stronger engagement from the research community and the growing use of AI to support security research.

The implication is that researchers may be generating and testing more leads than before, potentially speeding up discovery. At the same time, higher submission volume can increase workload for triage and coordination, making program operations and communication particularly important.

How this compares to prior years

Microsoft also provided context by looking backward at payout totals. The company said it paid out roughly $17 million across 2024 and 2025. It also reported about $13 million every year between 2020 and 2023.

While year-to-year comparisons are never perfectly apples-to-apples, the trend Microsoft describes suggests that its bug bounty programs have expanded in effectiveness and reach. Higher annual payouts can reflect more eligible reports, broader researcher participation, and stronger alignment between reported issues and remediation priorities.

Not all researchers are satisfied with report handling

Despite the positive payout metrics, the story is not universally welcomed. Microsoft’s update is accompanied by criticism from at least one researcher who claims the company mishandled vulnerability coordination and related processes.

A researcher using the moniker Chaotic Eclipse (also referenced as Nightmare Eclipse) described details of several zero-days without providing Microsoft an opportunity to patch them. Microsoft’s report handling has therefore been framed by the researcher as insufficient to enable timely remediation.

The researcher also alleged that some of the flaws were exploited after disclosure in the real world. In addition, the researcher claimed dissatisfaction with multiple aspects of the interaction, including allegations that communications were ignored, bounty payments were withheld, and an account used for reporting was deleted. The researcher further claimed that these actions breached a prior agreement.

For defenders and researchers alike, disputes like this highlight an ongoing challenge in vulnerability programs: even when awards and payouts are substantial, the operational experience around report triage, timing, and communication can still drive trust—or mistrust.

What Microsoft’s numbers signal for defenders

From a security leadership perspective, Microsoft’s reported outcomes suggest that its Microsoft bug bounty programs are creating measurable security value. More eligible reports, a large number of awarded researchers, and significant payouts indicate that the company is engaging with an active global research community.

For organizations that rely on Microsoft products or ecosystem components, improved vulnerability discovery and reward pathways can translate into faster identification of security issues and more consistent pressure to patch. Additionally, initiatives targeting third-party and open source components point toward broader risk coverage beyond first-party vulnerabilities.

What researchers can take away

For security researchers considering submission, the update provides a sense of the scale and incentives involved. With awards reaching $200,000 and hundreds of researchers rewarded, the program ecosystem clearly recognizes a variety of findings.

At the same time, the criticism noted in connection with zero-day disclosure serves as a reminder that researchers also weigh trust in the process. When researchers feel coordination fails, they may choose different disclosure approaches, which can affect timelines and the likelihood of exploitation.

Conclusion

Microsoft’s latest bug bounty update states that more than $20 million was paid out over the last year through its Microsoft bug bounty programs, with 562 researchers receiving awards from 2,531 eligible reports. The company also incorporated contest rewards from Zero Day Quest and added new initiative payouts for vulnerabilities in third-party and open source code.

While the numbers reflect expanding engagement and higher submission volume—potentially supported by AI-assisted research—the broader conversation includes researcher concerns about report handling. Together, these details show that vulnerability programs are both an incentives engine and a complex coordination system that depends on trust, speed, and clear communication.

Source: https://www.securityweek.com/microsoft-bug-bounty-program-20-million-paid-to-500-researchers/