Microsoft’s Bug Bounty Program Hits $20 Million Record as AI Reshapes Vulnerability Discovery

Artificial intelligence is accelerating both the finding and the reporting of vulnerabilities, with consequences for patch management that security teams cannot ignore.

AI-generated illustration depicting ai security for the story: Microsoft's Bug Bounty Program Hits $20 Million Record as AI Reshapes Vulnerability Discovery

Summary

  • Microsoft paid more than $20 million to 562 researchers in its 2024–25 bounty year, a company record up from $17 million the prior year.
  • A December 2025 policy change expanding eligible scope and a $2.3 million live hacking event accounted for a meaningful portion of the increase.
  • Microsoft attributes a surge in external submissions partly to researchers using AI tools, mirroring its own internal AI-driven vulnerability discovery.
  • July 2025 Patch Tuesday reached 622 vulnerabilities, more than triple the previous record set only a month earlier in June.
  • A researcher publishing zero-days outside coordinated disclosure — following a breakdown in their relationship with Microsoft — has prompted at least two others to follow suit.

Record payouts, record reports

Microsoft’s bug bounty program for the year ending 30 June 2026 paid out more than $20 million to 562 researchers, surpassing the previous record of roughly $17 million to 344 researchers. The jump in participation is partly structural: in December 2025 Microsoft adopted an ‘In Scope By Default’ policy, making critical vulnerabilities eligible for reward even when the underlying code belongs to a third party or an open source project, provided there is a direct and demonstrable impact on Microsoft’s online services. The company says this expanded scope accounted for $800,000 in rewards that would not previously have been available, and a further $2.3 million flowed through Zero Day Quest, Microsoft’s security research challenge and live hacking event.

AI on both sides of the fence

Microsoft attributes part of the spike in external submissions during the second half of the bounty year to what it describes as the growing use of AI to support security research. That mirrors what is happening inside Redmond: Microsoft has also linked its increasingly crowded Patch Tuesdays to its own use of advanced AI models for vulnerability discovery. The numbers bear this out starkly. April 2025 was described at the time as Microsoft’s second-biggest Patch Tuesday on record with 165 vulnerabilities. May came in at 137, June surpassed April with 206, and then July shattered every prior benchmark with 622 vulnerabilities — more than three times June’s figure. Pavan Davuluri, Microsoft’s Executive Vice President of Windows and Devices, acknowledged before the July release that customers should expect higher patch volumes now that AI plays a significant role in discovery, noting the company offers automated patching tools to ease the burden.

Coordinated disclosure under strain

Beyond the volume story, Microsoft is also navigating a more adversarial dynamic in vulnerability research. A researcher operating under the name NightmareEclipse spent the second quarter of 2025 publishing sophisticated zero-days outside any coordinated disclosure process. The vulnerabilities disclosed include serious privilege escalation flaws leading to SYSTEM access and BitLocker bypasses. NightmareEclipse claims their earlier attempts to report vulnerabilities to Microsoft through proper channels resulted in being insulted and humiliated. The sources do not independently verify those claims. Microsoft responded by signalling it was prepared to involve its Digital Crimes Unit, a move that does not appear to have resolved the situation. According to the source material, at least two other researchers have since adopted a similar approach of publishing exploit code outside responsible disclosure, suggesting the dynamic may be contagious.

Researcher motivations and programme friction

The source material notes that legitimate researchers navigating Microsoft’s submissions process found it frustrating at times, even as participation climbed. The combination of a cumbersome reporting experience and, in at least some cases, reportedly poor handling of researcher relationships creates a reputational risk for Microsoft’s ability to attract good-faith disclosure. The NightmareEclipse situation also raises an unresolved question noted in the source material: unverified speculation that the researcher may be a former Microsoft employee with deep internal knowledge of the software. Microsoft has not confirmed or denied this publicly, per the available sources.

Why it matters

For CISOs running organisations that depend on the Microsoft stack, the core risk here is patch cadence. A Patch Tuesday delivering 622 vulnerabilities is not a manageable event under traditional monthly patch governance; it demands triage automation and prioritisation frameworks that can handle genuine volume at speed. The AI-accelerated discovery cycle appears to be a structural shift rather than an anomaly, so patch programmes designed around last year’s volumes are already undersized. Separately, the breakdown in coordinated disclosure with NightmareEclipse and its apparent effect on other researchers is a reminder that the vulnerability ecosystem depends on researchers choosing responsible paths — and that path becomes less attractive when vendor relationships are perceived as hostile. Organisations cannot control Microsoft’s researcher relations, but they can maintain threat intelligence feeds for zero-days published outside coordinated disclosure and shorten their window for applying critical patches when exploit code is already public.

What to do now

  • Review your Microsoft patch triage and prioritisation process against the new normal of significantly higher monthly vulnerability volumes.
  • Assess whether your automated patching tooling — including Microsoft’s own offerings — can handle the increased throughput without creating operational risk.
  • Establish or refresh monitoring for zero-days published outside coordinated disclosure, particularly for Microsoft products, given the current adversarial disclosure environment.
  • Ensure BitLocker and privilege escalation mitigations are current, as these were among the vulnerability classes published outside responsible disclosure in recent months.
  • Factor the expanded ‘In Scope By Default’ bounty policy into your own third-party and open source software risk assessments, as components you use may now attract greater external scrutiny.

Sources