Feed
Bounty Rolling

Adobe bug bounty program on Intigriti

Adobe moved its bug bounty to Intigriti on 1 September 2026. Rewards go up to $15,000, with a bonus tier for Adobe AI features.

The Adobe Bug Bounty Program went live on Intigriti on 1 September 2026. Adobe announced the move on its security blog on 3 August 2026. All new reports now go through Intigriti.

Rewards follow CVSS severity and the asset tier. On the top tier a report scored 9.5 to 10 pays $10,000 to $15,000, a score of 9.0 to 9.4 pays $7,500 to $10,000 and a high report pays $1,500 to $7,500. Lower tiers pay less, from $75 for a low report up to $10,000 for a critical one.

The top tier is a bonus tier for Adobe AI features, such as Acrobat AI Assistant, Photoshop AI Assistant and Adobe Firefly AI features. The scope also covers mobile apps, Acrobat Web, Lightroom and Photoshop on the web, Adobe Express, Adobe Commerce and Magento, ColdFusion and Adobe account services.

AI assisted discovery is allowed, but the researcher must check the finding. Unchecked AI output is closed as not applicable. A report must be new, reproducible, in scope and include the tester's IP address. Adobe says it validates critical reports within two working days.

The program has no deadline. The Intigriti page shows it as active, with recent researcher activity.

Source · blog.adobe.com/security/a-new-home-for-the-adobe-bug-bounty-program Published 3 August 2026 · Added here 27 September 2026