Microsoft (bounty programs)

Microsoft (bounty programs)

Top 100 site
Partial Safe Harbor

Known Exploited Vulnerabilities 388CVEs

115 linked to ransomware campaigns

  • CVE-2026-81963WindowsSep 8, 2026

    Microsoft Windows Update Stack contains a link following vulnerability that allows a local attacker to escalate privileges locally up to SYSTEM.

  • CVE-2026-85880WindowsSep 8, 2026

    Microsoft Windows Advanced Local Procedure Call contains a heap-based buffer overflow vulnerability that allows an attacker to elevate privileges locally.

  • CVE-2019-1068SQL ServerAug 26, 202652.8% EPSS

    Microsoft SQL Server contains a remote code execution vulnerability that could allow an attacker to execute code in the context of the SQL Server Database Engine service account.

  • CVE-2026-33824Internet Key Exchange (IKE) Service ExtensionsAug 18, 202672.7% EPSS

    Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enable remote code execution.

  • CVE-2026-55040SharePointAug 18, 202639.7% EPSS

    Microsoft SharePoint contains a weak authentication vulnerability which allows an unauthorized attacker to bypass a security feature over a network.

  • CVE-2026-68820Windows Ancillary Function Driver for WinSock Aug 11, 20266.2% EPSS

    Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.

  • CVE-2026-50522SharePointJul 22, 202684.6% EPSS

    Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network.

  • CVE-2026-58644SharePointJul 16, 202615.9% EPSS

    Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.

  • CVE-2026-56155Active Directory Federation ServicesJul 14, 20260.3% EPSS

    Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally.

  • CVE-2026-56164SharePoint ServerJul 14, 202626.6% EPSS

    Microsoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to elevate privileges over a network.

and 378 more - view full CISA catalog →

security.txt

Contact
https://msrc.microsoft.com/report/vulnerability/new
Encryption
https://msrc.microsoft.com/.well-known/csaf/openpgp/998D7EC1A516E3D17FF90480EF148D3CDE714E0D.asc
Policy
https://www.microsoft.com/en-us/msrc/bounty-safe-harbor
Acknowledgments
https://msrc.microsoft.com/update-guide/acknowledgement
Languages
en
Expires
Sep 23, 2026
View raw security.txt →