Microsoft distributed a total of 20 million US dollars through its Bug Bounty program between July 1, 2025, and June 30, 2026. The company stated that the program saw 'significant growth' during this period.

During this fiscal year, 562 security researchers from 64 countries received payouts. The average payout per researcher was approximately 35,600 US dollars.

200,000 US dollars

Highest single payout for a single bug

Expansion of program scope

At the end of 2025, Microsoft expanded its Bug Bounty program to include findings in open-source and third-party projects used by the company, provided they have a direct impact on its services. This expansion resulted in more than 800,000 US dollars in rewards and over 300 additional reports.

Microsoft attributed the increase in submission volume to the strong engagement of the research community and the increasing use of AI to support security research.

Zero Day Quest and competition results

In early 2026, Microsoft held its in-house hacking competition, Zero Day Quest. Participants primarily targeted the company's cloud and AI platforms. The competition resulted in nearly 700 security vulnerabilities being discovered and 2.3 million US dollars in prize money being distributed.

Year-over-year comparison

In the previous period from mid-2024 to mid-2025, Microsoft distributed approximately 17 million US dollars to 344 researchers from 59 countries. The average payout per researcher in that year was approximately 49,400 US dollars.