AppNexus · Vulnerability Disclosure

Appnexus Vulnerability Disclosure

Vulnerability disclosure

AppNexus runs a coordinated vulnerability disclosure program on Hackerone.

CompanyAdTechAdvertisingProgrammaticAd ExchangeDSPSSPMobile SDKMarketing
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

appnexus-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-12'
method: searched
source: https://www.microsoft.com/.well-known/security.txt
api: Digital Platform API
provider_hosted: false
ownership_note: >-
  AppNexus/Xandr no longer runs a disclosure program of its own. appnexus.com and
  xandr.com serve no security.txt (see well-known/appnexus-well-known.yml - both domains
  301 to about.ads.microsoft.com, whose SPA answers 200 with an HTML shell for every
  path). Xandr has been a Microsoft product line since the 2022 acquisition, and the
  Microsoft Security Response Center is the disclosure channel that actually covers the
  Xandr / Microsoft Monetize online services. The program below is therefore the PARENT
  company's, recorded as such rather than attributed to an appnexus.com surface.
program:
  name: Microsoft Security Response Center (MSRC)
  operator: Microsoft Corporation
  report_url: https://msrc.microsoft.com/report/vulnerability
  report_url_status: 200
  policy_url: https://www.microsoft.com/en-us/msrc/cvd
  security_txt: https://www.microsoft.com/.well-known/security.txt
  security_txt_status: 200
  security_txt_host: www.microsoft.com
  self_hosted_on_provider_domain: false
bug_bounty:
  present: true
  name: Microsoft Bug Bounty Program
  url: https://www.microsoft.com/en-us/msrc/bounty
  url_status: 200
  platform: self-operated (MSRC), not HackerOne/Bugcrowd/Intigriti
  note: >-
    Microsoft's Online Services bounty scope is the one that would cover the Monetize /
    Invest platform surface. Xandr-specific scope wording is not published separately.
probes:
- url: https://api.appnexus.com/.well-known/security.txt
  status: 404
- url: https://www.appnexus.com/.well-known/security.txt
  status: 301
  resolved_status: 200
  verdict: miss
  reason: redirects to about.ads.microsoft.com SPA catch-all, HTML not RFC 9116 text
- url: https://www.xandr.com/.well-known/security.txt
  status: 301
  resolved_status: 200
  verdict: miss
  reason: redirects to about.ads.microsoft.com SPA catch-all, HTML not RFC 9116 text
- url: https://www.microsoft.com/.well-known/security.txt
  status: 200
  verdict: hit
  scope: parent company
- url: https://msrc.microsoft.com/report/vulnerability
  status: 200
  verdict: hit
  scope: parent company
gap:
  finding: >-
    A researcher who finds a flaw in api.appnexus.com has no machine-discoverable route
    to report it from that host. Publishing an RFC 9116 security.txt on api.appnexus.com
    pointing at MSRC would close this with one file.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/appnexus-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.