Microsoft distributed a total of 20 million US dollars through its Bug Bounty program between July 1, 2025, and June 30, 2026. The company stated that the program saw 'significant growth' during this period.
During this fiscal year, 562 security researchers from 64 countries received payouts. The average payout per researcher was approximately 35,600 US dollars.
Highest single payout for a single bug
Expansion of program scope
At the end of 2025, Microsoft expanded its Bug Bounty program to include findings in open-source and third-party projects used by the company, provided they have a direct impact on its services. This expansion resulted in more than 800,000 US dollars in rewards and over 300 additional reports.
Microsoft attributed the increase in submission volume to the strong engagement of the research community and the increasing use of AI to support security research.
Zero Day Quest and competition results
In early 2026, Microsoft held its in-house hacking competition, Zero Day Quest. Participants primarily targeted the company's cloud and AI platforms. The competition resulted in nearly 700 security vulnerabilities being discovered and 2.3 million US dollars in prize money being distributed.
Year-over-year comparison
In the previous period from mid-2024 to mid-2025, Microsoft distributed approximately 17 million US dollars to 344 researchers from 59 countries. The average payout per researcher in that year was approximately 49,400 US dollars.