Microsoft rewarded 562 security researchers from 64 countries with a total of $20 million through its Bounty Program, marking a record payout driven by a surge in vulnerability disclosures. This program incentivizes experts to identify and report security flaws across Microsoft’s diverse products and services, ranging from cloud platforms to consumer software.
The amount researchers receive varies depending on the vulnerability type. Cloud-related and Zero Day Quest reports can earn up to $100,000 per finding, while issues in Endpoint and On-Premises programs may receive awards of up to $250,000. Although these represent maximum figures, many submissions result in smaller payments based on severity and impact.
Expanding the program’s scope last year, Microsoft began offering bounties not only on its own software but also for vulnerabilities discovered in open-source projects, third-party components, and cloud services critical to customers’ security. The company highlights the crucial role of this collaboration in preemptively addressing risks before they can be exploited maliciously.
Advancements in artificial intelligence have played a dual role in this landscape. Security researchers increasingly deploy AI tools to discover and report weaknesses more efficiently, while Microsoft also integrates AI in its own vulnerability detection and remediation efforts. Conversely, hackers leverage AI to rapidly exploit known vulnerabilities, creating a high-stakes “arms race” between defenders and attackers in cyberspace.
Microsoft also reflected on its Zero Day Quest event, which gathered researchers from 20 countries at the company’s headquarters. Over 700 vulnerabilities were submitted during the challenge, and the event alone awarded more than $2.3 million, underscoring the global scale and intensity of efforts to enhance software security.

