Microsoft Expands Bug Bounty Program to Open Source and Third-Party Code, Pays Record $20 Million
Microsoft's bounty program paid over $20 million to 562 researchers this year after expanding scope to cover open-source software and third-party components.
Overview
Microsoft has broadened its bug bounty program to cover vulnerabilities found in open-source software and third-party components, not just its own products, according to a year-in-review post from the Microsoft Security Response Center (MSRC). The company said it paid out “more than $20 million awarded in our biggest year yet” to security researchers over the program year, according to MSRC.
What We Know
The expanded program year ran from July 1, 2025, to June 30, 2026, according to Open Source For You. During that period, Microsoft rewarded 562 security researchers from 64 countries, according to MSRC, an increase from the prior year’s $17 million paid to 344 researchers from 59 countries, according to MSRC. The 562 researchers received an average of approximately $35,000 each, according to Open Source For You.
Microsoft said it “expanded our vulnerability awards portfolio to recognize impactful research beyond traditional bounty scopes, including eligible open-source software, third-party components, and Microsoft cloud services,” according to MSRC. The broader scope generated more than 300 additional vulnerability reports that would not have qualified under the program’s previous rules, and Microsoft paid out more than $800,000 specifically for those newly eligible findings, according to MSRC. Open Source For You reported that the move reflects “the growing reliance of modern products on open-source software, external libraries, and interconnected cloud services, where vulnerabilities in upstream components can affect multiple Microsoft products.”
Separately from the broader bounty program, Microsoft’s Zero Day Quest event brought researchers from 20 countries to the company’s Redmond campus to collaborate directly with its security and engineering teams, according to MSRC. Participants at that event submitted nearly 700 vulnerability reports focused on Microsoft’s cloud and AI platforms and collected $2.3 million in awards, according to MSRC and confirmed by ITPro, which reported the same reports-submitted and awards-earned figures independently.
Per-vulnerability award caps differ by program, according to ITPro: cloud-program and Zero Day Quest vulnerabilities are capped at $100,000 each, while endpoint and on-premises program vulnerabilities can earn researchers up to $250,000.
MSRC closed its review with a statement framing the expansion as part of a broader security posture, according to MSRC: “Security is a team sport. Every vulnerability reported through our bounty programs represents an opportunity to address risk before it can be exploited against customers. The work of the research community plays a critical role in helping Microsoft stay ahead of emerging threats while strengthening the security of cloud services, AI systems, enterprise platforms, and consumer technologies.”
What We Don’t Know
Microsoft’s post does not name which specific open-source projects or third-party components are now in scope, nor does it detail the review or triage process for reports involving code Microsoft does not own. It is also not clear how the $800,000 paid for newly eligible findings is distributed across the more than 300 reports, or how many of those reports have resulted in patches shipped to the affected upstream projects.