Microsoft Paid More Than $20 Million in Bug Bounties Microsoft Corp. said on August 3 that its vulnerability rewards programs awarded more than $20 million to 562 security researchers from 64 countries during the fiscal year ended June 30, 2026, both program records, with its Zero Day Quest contributing $2.3 million of the total. Microsoft received 2,531 eligible reports across 15 bounty programs, and the largest individual award was $200,000, according to SecurityWeek. Microsoft attributed a notable increase in submissions during the second half of the year to strong researcher participation and the growing use of AI in security research, though it did not disclose how many accepted reports used AI. Microsoft Paid More Than $20 Million in Bug Bounties Microsoft said on August 3 that its bounty programs awarded more than $20 million to 562 security researchers during the year ended June 30, 2026, both program records. Researchers from 64 countries submitted findings across Microsoft products, while the company's Zero Day Quest accounted for $2.3 million of the total. Microsoft said its vulnerability rewards programs awarded more than $20 million to 562 security researchers during the year ended June 30, 2026. The August 3 announcement described both figures as records for the program and said participants came from 64 countries. SecurityWeek reported that Microsoft received 2,531 eligible reports across 15 bounty programs and that the largest individual award was $200,000. Those figures cover the company's fiscal-year bounty activity rather than a single contest or vulnerability. Where the awards went Microsoft said Zero Day Quest, its cloud- and AI-focused research challenge and live hacking event, drew researchers from 20 countries. Participants submitted nearly 700 vulnerability reports and earned $2.3 million. The company also reported more than 300 additional submissions and over $800,000 in awards after broadening its rewards portfolio to cover eligible open-source software, third-party components and Microsoft cloud services. SecurityWeek noted that the overall program spans products including Azure, Microsoft 365, Windows, Edge, Xbox and Dynamics 365. AI is changing submission volume Microsoft attributed a notable increase in submissions during the second half of the year to strong researcher participation and the growing use of AI in security research. That is a company assessment, not a measured breakdown of how many accepted reports were found with AI. The distinction matters for security teams. Higher discovery volume can expose more defects before attackers do, but it also increases the work required to reproduce reports, assess exploitability, coordinate fixes and communicate risk. The record payout is therefore evidence of both broader researcher participation and a larger validation pipeline. Microsoft's announcement does not identify the vulnerabilities behind the largest awards or quantify the share of reports that used AI. Those missing details limit conclusions about whether AI-assisted submissions were more severe or more productive than conventional research. Key Points - 1Microsoft awarded more than $20 million to 562 researchers from 64 countries during the year ended June 30, 2026. - 2Zero Day Quest contributed nearly 700 vulnerability reports and $2.3 million in awards focused on Microsoft's cloud and AI platforms. - 3Microsoft linked higher submission volume partly to AI-assisted security research but did not disclose how many accepted reports used AI. Scoring Rationale The record payout and researcher count quantify the scale of Microsoft's vulnerability-disclosure program and show AI-assisted research increasing submission volume, with practical implications for vulnerability triage and coordinated remediation. Sources Primary source and supporting public references used for this report. Practice interview problems based on real data 1,625 SQL & Python problems across 15 industry datasets — the exact type of data you work with. Try 250 free problems /problems