AppNexus · Vulnerability Disclosure
Appnexus Vulnerability Disclosure
Vulnerability disclosure
AppNexus runs a coordinated vulnerability disclosure program on Hackerone.
CompanyAdtechAdvertisingProgrammaticAd ExchangeDSPSSPMobile SDKMarketing
Program: Hackerone
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
generated: '2026-08-12'
method: searched
source: https://www.microsoft.com/.well-known/security.txt
api: Digital Platform API
provider_hosted: false
ownership_note: >-
AppNexus/Xandr no longer runs a disclosure program of its own. appnexus.com and
xandr.com serve no security.txt (see well-known/appnexus-well-known.yml - both domains
301 to about.ads.microsoft.com, whose SPA answers 200 with an HTML shell for every
path). Xandr has been a Microsoft product line since the 2022 acquisition, and the
Microsoft Security Response Center is the disclosure channel that actually covers the
Xandr / Microsoft Monetize online services. The program below is therefore the PARENT
company's, recorded as such rather than attributed to an appnexus.com surface.
program:
name: Microsoft Security Response Center (MSRC)
operator: Microsoft Corporation
report_url: https://msrc.microsoft.com/report/vulnerability
report_url_status: 200
policy_url: https://www.microsoft.com/en-us/msrc/cvd
security_txt: https://www.microsoft.com/.well-known/security.txt
security_txt_status: 200
security_txt_host: www.microsoft.com
self_hosted_on_provider_domain: false
bug_bounty:
present: true
name: Microsoft Bug Bounty Program
url: https://www.microsoft.com/en-us/msrc/bounty
url_status: 200
platform: self-operated (MSRC), not HackerOne/Bugcrowd/Intigriti
note: >-
Microsoft's Online Services bounty scope is the one that would cover the Monetize /
Invest platform surface. Xandr-specific scope wording is not published separately.
probes:
- url: https://api.appnexus.com/.well-known/security.txt
status: 404
- url: https://www.appnexus.com/.well-known/security.txt
status: 301
resolved_status: 200
verdict: miss
reason: redirects to about.ads.microsoft.com SPA catch-all, HTML not RFC 9116 text
- url: https://www.xandr.com/.well-known/security.txt
status: 301
resolved_status: 200
verdict: miss
reason: redirects to about.ads.microsoft.com SPA catch-all, HTML not RFC 9116 text
- url: https://www.microsoft.com/.well-known/security.txt
status: 200
verdict: hit
scope: parent company
- url: https://msrc.microsoft.com/report/vulnerability
status: 200
verdict: hit
scope: parent company
gap:
finding: >-
A researcher who finds a flaw in api.appnexus.com has no machine-discoverable route
to report it from that host. Publishing an RFC 9116 security.txt on api.appnexus.com
pointing at MSRC would close this with one file.