Vulnerability Disclosure Program (VDP)

VDPs are meant for responsibly reporting vulnerabilities you encounter — not for actively hunting for fame or reputation. Even if you're just starting out, consider focusing on rewarded bug bounty programs instead.

msd

HackerOneView on HackerOne
RawAI Enhanced
3
In Scope
0
Out of Scope
In-Scope Assets (3)
AssetCategoryBountyQuick Links
*.merck.comURLNo
*.msd.comURLNo
All other applications (web sites, web applications, web services, and mobile applications) owned by Merck & Co., Inc., Rahway, NJ, USAOTHERNo-
Scope Changes (9)
Feb 26, 2026
ChangeAssetCategoryScopeTime
Added*.merck.comWILDCARDIn Scope02:52
Added*.msd.comWILDCARDIn Scope02:52
Addedall other applications (web sites, web applications, web services, and mobile applications) owned by merck & co., inc., rahway, nj, usaOTHERIn Scope02:52
Feb 22, 2026
ChangeAssetCategoryScopeTime
Added*.merck.comWILDCARDIn Scope00:40
Added*.msd.comWILDCARDIn Scope00:40
Addedall other applications (web sites, web applications, web services, and mobile applications) owned by merck & co., inc., rahway, nj, usaOTHERIn Scope00:40
Feb 21, 2026
ChangeAssetCategoryScopeTime
Added*.merck.comURLIn Scope19:11
Added*.msd.comURLIn Scope19:11
Addedall other applications (web sites, web applications, web services, and mobile applications) owned by merck & co., inc., rahway, nj, usaOTHERIn Scope19:11