MEDIUMVulnerability
Global

Microsoft Bug Bounty Program: $20 Million Paid to 500 Researchers

·Source: SecurityWeek

Updated:

Executive Summary

The biggest single reward paid out by Microsoft between July 1, 2025, and June 30, 2026, was $200,000. The post Microsoft Bug Bounty Program: $20 Million Paid to 500 Researchers appeared first on SecurityWeek .

Analysis

The biggest single reward paid out by Microsoft between July 1, 2025, and June 30, 2026, was $200,000. The post Microsoft Bug Bounty Program: $20 Million Paid to 500 Researchers appeared first on SecurityWeek .
Source Attribution

Originally published by SecurityWeek on Aug 4, 2026.

Related Threats

HIGHVulnerability

NVD HIGH: CVE-2026-42169 — A heap-buffer-overflow vulnerability exists in the APNG (Animated PNG) file load...

A heap-buffer-overflow vulnerability exists in the APNG (Animated PNG) file loader of GIMP. This flaw occurs when the `fcTL` width exceeds the `IHDR` width, leading to pixel data being written past the end of a heap allocation. Additionally, a heap-based buffer overflow exists in the DDS plug-in due to a BPP mismatch in the `load_layer()` function. Both vulnerabilities can be triggered by opening

CVE-2026-42169
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-14818 — A path traversal vulnerability in the CLI command used to execute configuration ...

A path traversal vulnerability in the CLI command used to execute configuration files in Zyxel ATP series firmware versions from V4.32 through V5.42 Patch 1, USG FLEX series firmware versions from V4.50 through V5.42 Patch 1, USG FLEX 50(W) series firmware versions from V4.16 through V5.42 Patch 1, and USG20(W)-VPN series firmware versions from V4.16 through V5.42 Patch 1 could allow an authentica

CVE-2026-14818
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-6837 — A post-authentication command injection vulnerability in the "export-cgi" CGI pr...

A post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device.

CVE-2026-6837
NIST NVD