Placeholder
Bitdefender Cybersecurity
  • For Consumer
    • All-in-one plans
      All-in-One Plans
      • Ultimate Security
      • Premium Security
      • Total Security
      • Ultimate Small Business Security
      • Security for Creators
      View All
      Device Security
      • Internet Security
      • Antivirus Plus
      • Antivirus for Mac
      • Mobile Security for Android
      • Mobile Security for iOS
      • Family Pack
      • Small Office Security
      View All
      Try Bitdefender
      • Scamio - Scam Detector AI Powered
      • Password Generator NEW
      • Link Checker NEW
      • Antivirus Free
      • Antivirus Free for Android
      • Trial Downloads
      View All
      Existing Customers
      • Renew
      • Support
      Quick Links
      • Join Our Community
      • Smart Home Cybersecurity
      • Cyberpedia
    • Privacy & Identity Protection
      Privacy
      • Premium VPN
      • SecurePass
      Identity Protection
      • Digital Identity Protection
      • Identity Theft Protection
  • For Small Business
  • For Enterprise
    • Platform
      GravityZone Platform - Comprehensive Unified Security
      Endpoint Security Packages
      • Small Business Security Buy Online
      • Business Security
      • Business Security Premium
      • Business Security Enterprise
      • Compare Packages
      • Demo Zone NEW
      • Free Trials
      View All
      Managed Service Providers
      • Cloud MSP Security
      • Security for MSSPs
      • Managed Detection and Response for MSPs
      Extended Detection and Response
      • Extended Detection and Response (XDR)
      • Endpoint Detection and Response (EDR)
      • Identity Threat Detection and Response (ITDR)
      Cloud Security
      • Cloud Native Security
      • Cloud Workload Security
      • Security for Containers
      • CSPM+
      Risk Management & Compliance
      • GravityZone PHASR NEW
      • Compliance Manager NEW
      • Risk Management
      • Vulnerability and Patch Management
      • Full Disk Encryption
      View All
      360 Degree Security
      • Security for Email
      • Security for Mobile
      • Operational Threat Intelligence
    • Services
      Managed Services
      • Managed Detection and Response
      • Managed Detection and Response PLUS
      • Managed Detection and Response for MSPs
      Security Services
      • Offensive Services
      • Support Services
      Support Services
      • Support Documentation
      • Premium Support
      • Professional Services
      Quick Links
      • Demo Zone NEW
      • MDR Insights
      • MITRE Engenuity for MDR
      • Gartner Market Guide for MDR
    • Why Bitdefender
      The Bitdefender Difference
      • AI-Powered Cybersecurity New
      • Fighting Cybercrime New
      • Customer Success Stories
      • Industry Recognition and Awards
      • Technology Alliances
      • Certifications
      • Bitdefender Labs and Research
      Solutions
      • Cloud Native Security
      • Enable Cyber Resilience
      • Improve Cybersecurity Compliance
      • Provide Managed Security Services
      • Secure Cloud Workloads
      • Secure Datacenters
      • Secure Endpoints
      • Secure Small to Medium Business
      Industries
      • Education
      • Energy and Utilities
      • Financial Services
      • Healthcare
      • Manufacturing
      • Public Sector
      • Technology
      • Telecommunications
      • Retail
      Compare Bitdefender
      • vs. Crowdstrike
      • vs. Huntress
      • vs. Microsoft
      • vs. SentinelOne
      • vs. Sophos
    • Resources
      Highlights
      • 2025 Cybersecurity Predictions
      • FunkSec: Ransomware Group
      • Akira Ransomware
      • ShrinkLocker (+Decryptor)
      Training & Education
      • InfoZone, Cybersecurity 101
      • TechZone, Technical Insights & Explainers
      • DemoZone, Interactive Demos NEW
      • Masterclasses, Onboarding Sessions NEW
      Resource Library
      • Newsroom
      • Blogs
      • Industry Recognition & Reports
      • Webinars
      • eBooks & Whitepapers
      • Case Studies
    • About
      • About the Business Solution Group
      • Leadership
      • Careers
      • Newsroom
    View Packages and Pricing
  • For Partners
    • Reseller Partners
      Our network
      • Reselling Partner Program Overview
      • Become a Reseller
      Quick Links
      • Log in to the Business Solutions Partners portal
      • Log in to the Consumer / VSB Solutions Partners portal
      • Find a Reseller
      • Already a Partner?
      • Join our Affiliates Program
      View All
    • Managed Service Providers
      Our Network
      • MSP Partner Program Overview
      • Become a MSP Partner
      Quick Links
      • Log In To PAN Portal
      • Find a MSP Partner
      • Already a Partner?
    • Technology Licensing
      Technology Licensing Portfolio
      • OEM Technology Solutions
      • Endpoint Protection SDKs
      • Gateway Protection SDKs
      • Sandbox Services
      • Reputation Threat Intelligence
      View All
      Licensing Options
      • SDK Integration
      • Rebranding
      • Bundling
      Quick Links
      • Contact Us
    • Telco Partners
      Resources Center
      • Subscriber Protection Platform
      • Resources
    • Technology Partners
      Technology Alliances
      • Technology Alliance Partner Program
  • Company
    • About Us
      • Overview
      • Management
      • Customers
      • Awards
      • Certifications
      • Careers
      View All
    • Latest News
      • Newsroom
      • Blogs
      • Bitdefender Cyberpedia
    • Resources
      • Research
      • White Papers
      • Industry Reports
      • Threat Maps
      View All
    • Brand
      • Why Trusted
      • The Bitdefender Difference
      • Ferrari Partnership
      • Cybersecurity Partner of Ferrari
      • Brand Portal
  • Blog
  • Support
    How Can We Help
    • Support for Home Products
    • Support for Business Products
  • Login
    Your Account
    • Bitdefender Central
    • GravityZone CLOUD Control Center
    • MDR Portal

Bitdefender Bug Bounty Program

Here you can check the Bitdefender hall of fame.

The Bug Bounty Reward program encourages security researchers to identify and submit vulnerability reports regarding virtually everything that bears the Bitdefender brand, including but not limited to the website, products and services.

We decided to offer rewards only for the following targets:

  • *.bitdefender.com
  • *.bitdefender.net
  • Bitdefender Total Security
  • Bitdefender GravityZone Business Security
  • Bitdefender Antimalware Engines
Exciting Update: Expanding Our Scope

In our continuous effort to enhance cybersecurity, Bitdefender has recently acquired Horangi Cyber Security. We are thrilled to announce the inclusion of Horangi Cyber Security in our bug bounty program. As such, we encourage researchers to also scrutinize and report vulnerabilities in *.horangi.com.

The following kinds of findings are specifically non-rewardable within this program:
  • Self XSS or other types of self-exploitation (cookie reuse, self DoS, self-cookie-bomb, etc.)
  • Descriptive error messages (e.g., stack traces, application or server errors).
  • Email spoofing issues (incomplete or lack of SPF, DMARC, DKIM records)
  • Out of date software versions
  • Content Spoofing
  • Vulnerabilities that are limited to unsupported browsers or operating systems
  • Password policies not enforced on user accounts
  • Clickjacking or any issue exploitable through clickjacking
  • Vulnerabilities in third-party software. Please reach out to the company responsible for the code to have the issues fixed. We may contact the upstream provider, depending on the impact of the vulnerability.
  • Lack of Secure and HTTPOnly cookie flags.
  • Username / email enumeration
  • CORS issues without a working PoC
  • Login or Forgot Password page brute force and account lockout not enforced
  • CSRF issues that have no security impact
  • Antimalware detections bypass or undetected malware samples
  • Local privilege elevation on Gravityzone On-Premises OS Recently disclosed critical vulnerabilities in third-party software where there is no patch, or a recent patch (less than one week) is available.
  • Missing HTTP security headers
  • TLS/SSL Issues, bad cipher suite, expired certificates, etc.
  • Internal IP address disclosure
  • Reports of spam (i.e., any report involving ability to send emails without rate limits).
  • Pre-Authentication Account Takeover
  • Mobile issues that require root access or unsupported OS versions
  • Non-sensitive exposed API keys (Google Maps, etc.).
  • Failure to invalidate session on password change or MFA change.
Out of scope targets

lsems.gravityzone.bitdefender.com
ssems.gravityzone.bitdefender.com
community.bitdefender.com
resellerportal.bitdefender.com
stats.bitdefender.com
sstats.bitdefender.com
brand.bitdefender.com
partner-marketing.bitdefender.com
businessinsights.bitdefender.com
businessemail.bitdefender.com
businessresources.bitdefender.com
oemhub.bitdefender.com
oemresources.bitdefender.com
crp.bitdefender.com
telcosuccess.bitdefender.com
demo.bitdefender.com

Program Terms

Participation in the Bitdefender Bug Bounty Reward program is voluntary and subject to the legal terms and conditions detailed on Terms and Conditions page. By submitting a vulnerability report to Bitdefender, you acknowledge that you have read and agreed to our program terms.

Qualification Criteria

The program covers any exploitable vulnerability that can compromise the integrity of our user data, crash applications (leading to compromise of data) or disclose sensitive information (for example remote code execution, SQL injection, Cross-Site Scripting, Cross-Site Request Forgery, information disclosure of sensitive data, authentication theft or bypass, clickjacking).

Make sure your submission report includes the proof of concept and replication information.

Non-qualifying vulnerabilities

Submissions that include just the output of automated tools will be marked as invalid. You must clearly outline the attack vectors and reproduction steps to accomplish the compromise

Submission process

We encourage you to send your submissions in an encrypted format to 

 bugbounty@bitdefender.com

We prefer PGP and you can import our public key from here. Make sure your report includes:

  • A clear and relevant title
  • Affected product / service
  • Vulnerability details and impact
  • Reproduction steps / Proof of Concept
Rewards

There is no fixed price for submissions. They will all be evaluated and rewards will be issued based on impact. Obviously an XSS submission will value less than RCE.

The minimum reward is set at $100. We’re not setting an upper limit on rewards at this time. The rewards will be issued if you are the first one to submit a specific vulnerability and your report is determined to address a valid issue by our response team.

IMPORTANT
  • This program is open to participants worldwide, excluding locations where prohibited by law, who have reached the age of majority in his/her country, province or territory of residence.
  • Participants are responsible for any tax implications depending on the country of residency and citizenship. There may be additional restrictions on a participant’s ability to enter the program, depending upon local law.
  • Determining the validity and value of a submission lies exclusively with our team. We trust you to tinker with our technologies and you’ll have to trust us to be fair in our evaluation.

When does it start?
The Bitdefender Bug Bounty Program opened on 10th December 2015.

HotForSecurity Latest news
  • Bitdefender and SFR Partner to Deliver Advanced Cybersecurity Solutions Across France
  • Bitdefender Named a Strong Performer in Extended Detection and Response (XDR) Report by Leading Research Firm
  • New Bitdefender Report Reveals Majority of Online Consumers Practice Risky Behavior for Data Protection, Digital Identity and Device Management
HOTforSecurity
  • How to Keep Your Devices and Personal Data Safe on Summer Vacation
  • Don’t name your Wi-Fi hotspot this, unless you want to crash your iPhone
  • Repairmen suspected of installing ransomware on customers’ PCs. Arrests in South Korea
Videos
  • The Mind Online Podcast: De ce suntem atât de furioși online?
  • 20 YEARS OF CYBERSECURITY INNOVATION | ALWAYS DEFENDING
  • Update-Chamäleon
Security Guides
  • Tips and tricks on how to keep your blog and your identity safe
  • Tips and tricks on how to shield your home network from intruders
Quick Helpers
  • TrafficLight
Books

Test the Bitdefender products

Available Now

Become a more cyber resilient business today

We’re here to help you choose the solution or service that’s right for your business

Start Free Trial
Contact Us
b-red-mask
cta-circle
Bitdefender Cybersecurity
  • For Consumer
  • For Small Business
  • For Enterprise
  • For Partners
  • Company

Follow Bitdefender

  • Facebook
  • Twitter
  • Linkedin
  • Youtube
  • Instagram
  • TikTok

Quick Links

  • Bitdefender Central
  • Gravityzone Cloud Control Center
  • Bitdefender Cyberpedia
  • Partner Advantage Network Portal
  • Brand Portal
  • Support for Home Products
  • Support for Business Products
  • Investors
  • Careers
  • InfoZone

Quick Links

  • Bitdefender Central
  • Gravityzone Cloud Control Center
  • Bitdefender Cyberpedia
  • Partner Advantage Network Portal
  • Brand Portal
  • Support for Home Products
  • Support for Business Products
  • Investors
  • Careers
  • InfoZone
Choose Your Country
  • Australia - English
  • België - Nederlands
  • Belgique - Français
  • Belize - English
  • Brasil - Português
  • Bulgaria - English
  • Canada - English
  • Chile - Español
  • Colombia - Español
  • Czechia - English
  • Denmark - English
  • Deutschland - Deutsch
  • España - Español
  • France - Français
  • Hong Kong - China
  • Hungary - English
  • India - English
  • Indonesia - English
  • Israel - English
  • Italia - Italiano
  • Jamaica - English
  • Latvia - English
  • Malaysia - English
  • Malta - English
  • México - Español
  • Nederland - Nederlands
  • New Zealand - English
  • Norway - English
  • Österreich - Deutsch
  • Perú - Español
  • Philippines - English
  • Poland - English
  • Portugal - Português
  • România - Română
  • Saudi Arabia - English
  • Schweiz - Deutsch
  • Singapore - English
  • South Africa - English
  • South Korea - English
  • Sverige - Svenska
  • Taiwan - 台灣
  • Thailand - English
  • United Arab Emirates - English
  • United Kingdom - English
  • United States - English
  • 日本 - 日本語

Follow Bitdefender

  • Facebook
  • Twitter
  • Linkedin
  • Youtube
  • Instagram
  • TikTok

Trusted. Always.

  • Legal Information
  • Privacy Policy
  • Site Map
  • Contact Us

Copyright © 1997 - 2025 Bitdefender

  • 111 W. Houston Street, Suite 2105, Frost Tower Building, San Antonio, Texas 78205