logo

Microsoft now pays up to $40,000 for some .NET vulnerabilities

ID: 08cfad8b-afd9-5c5f-aa15-611ca0cb4528

STIX ID: report--08cfad8b-afd9-5c5f-aa15-611ca0cb4528

Feed Name: Bleeping Computer

Date Published: 2025-07-31

Date Updated: 2026-07-17

Author: Sergiu Gatlan

...
...

Microsoft has expanded its .NET bug bounty program, raising maximum awards to $40,000 for critical .NET and ASP.NET Core vulnerabilities (including remote code execution and privilege escalation) and increasing payouts for other bug classes; the program scope now covers all supported .NET/ASP.NET versions, adjacent technologies like F#, templates, and related GitHub Actions, and the article references Microsoft's broader security incentive efforts such as previous bounty increases and the Zero Day Quest.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.