AppNexus · Vulnerability Disclosure
Appnexus Vulnerability Disclosure
Vulnerability disclosure
AppNexus runs a coordinated vulnerability disclosure program on Hackerone.
CompanyAdTechAdvertisingProgrammaticAd ExchangeDSPSSPMobile SDKMarketing
Program: Hackerone
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
generated: '2026-08-12'
method: searched
source: https://www.microsoft.com/.well-known/security.txt
api: Digital Platform API
provider_hosted: false
ownership_note: >-
AppNexus/Xandr no longer runs a disclosure program of its own. appnexus.com and
xandr.com serve no security.txt (see well-known/appnexus-well-known.yml - both domains
301 to about.ads.microsoft.com, whose SPA answers 200 with an HTML shell for every
path). Xandr has been a Microsoft product line since the 2022 acquisition, and the
Microsoft Security Response Center is the disclosure channel that actually covers the
Xandr / Microsoft Monetize online services. The program below is therefore the PARENT
company's, recorded as such rather than attributed to an appnexus.com surface.
program:
name: Microsoft Security Response Center (MSRC)
operator: Microsoft Corporation
report_url: https://msrc.microsoft.com/report/vulnerability
report_url_status: 200
policy_url: https://www.microsoft.com/en-us/msrc/cvd
security_txt: https://www.microsoft.com/.well-known/security.txt
security_txt_status: 200
security_txt_host: www.microsoft.com
self_hosted_on_provider_domain: false
bug_bounty:
present: true
name: Microsoft Bug Bounty Program
url: https://www.microsoft.com/en-us/msrc/bounty
url_status: 200
platform: self-operated (MSRC), not HackerOne/Bugcrowd/Intigriti
note: >-
Microsoft's Online Services bounty scope is the one that would cover the Monetize /
Invest platform surface. Xandr-specific scope wording is not published separately.
probes:
- url: https://api.appnexus.com/.well-known/security.txt
status: 404
- url: https://www.appnexus.com/.well-known/security.txt
status: 301
resolved_status: 200
verdict: miss
reason: redirects to about.ads.microsoft.com SPA catch-all, HTML not RFC 9116 text
- url: https://www.xandr.com/.well-known/security.txt
status: 301
resolved_status: 200
verdict: miss
reason: redirects to about.ads.microsoft.com SPA catch-all, HTML not RFC 9116 text
- url: https://www.microsoft.com/.well-known/security.txt
status: 200
verdict: hit
scope: parent company
- url: https://msrc.microsoft.com/report/vulnerability
status: 200
verdict: hit
scope: parent company
gap:
finding: >-
A researcher who finds a flaw in api.appnexus.com has no machine-discoverable route
to report it from that host. Publishing an RFC 9116 security.txt on api.appnexus.com
pointing at MSRC would close this with one file.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/appnexus-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.