The July Patch Tuesday security rollout fixed a record-breaking 570 vulnerabilities across the Microsoft ecosystem. Of these, only two were actively being exploited by attackers before the patches were released. A vulnerability is not the same as an exploit, but it can become one if not mitigated before the threat actors get a chance. The work of security researchers, part of the Microsoft Bounty Program, is one of the reasons why so few such so-called zero-days make it into the wild. And across the last year, a record number of those security researchers have shared a record-breaking total bounty payout of $20 million. Those 562 researchers, from 64 different countries, helped “protect customers through coordinated vulnerability disclosure,” the company has confirmed in a Microsoft Security Response Center announcement.
As I have said many times before, hacking is not a crime. The distinction between what we used to refer to as ethical hacking, but is now more commonly referred to as bug hunting, and cybercrime is important and all too often misunderstood. Let’s be clear: without these bug hunters disclosing vulnerabilities in the platforms and applications we all use, through recognized vulnerability disclosure platforms, we would all find ourselves in a much less secure place than we currently are. As well as commercial programs operated by the likes of Bugcrowd, most of the big technology players also have their own schemes. Google’s Vulnerability Reward Program, for example, wasn’t far behind Microsoft, paying out $17 million in rewards last year.
Funnily enough, $17 million is the amount that Microsoft paid out researchers from the bounty program the previous year, a record at the time. This year, which in Microsoft’s bounty platform terms runs from June 2025 to July 2026, “brought significant growth across Microsoft’s vulnerability awards programs, helping us recognize more researchers and more impactful security findings,” a MSRC spokesperson said. Unsurprisingly, Microsoft also confirmed it had seen a “notable increase” in the number of vulnerability reports submitted, especially during 2026, which it said was partly due to “the growing use of AI to support security research.”
But AI alone is not enough; it takes skilled security researchers to ensure that red herrings are not forwarded as confirmed vulnerabilities in disclosure reports, to put these findings to the test and present them in the proper context for triage and mitigation. Indeed, the latest Microsoft Zero Day Quest live hacking event saw researchers submit 700 reports, earning $2.3 million in rewards, all while collaborating directly, in real time, with security and engineering teams at Microsoft’s Redmond campus.
All of which just goes to show that, despite recent hiccups that have seen one security researcher go head-to-head against MSRC and release zero-day vulnerabilities without prior disclosure or warning, a strong relationship between Microsoft and the security research community around the world is essential to help protect customers across all products and platforms. If you are interested in helping out, you can get more information about the Microsoft Bounty Program.

