Researchers at Pwn2Own Berlin 2026 earned $523,000 on the first day after demonstrating 24 unique zero-day vulnerabilities against fully patched targets spanning browsers, operating systems, AI platforms, and NVIDIA-related infrastructure. The standout exploit came from Orange Tsai of DEVCORE Research Team, who chained four logic bugs to escape the Microsoft Edge sandbox and collected $175,000. Windows 11 was also successfully compromised three times through separate local privilege-escalation zero-days, underscoring continued risk in core desktop platforms.
Other successful demonstrations targeted Red Hat Linux for Workstations, NVIDIA Container Toolkit, NVIDIA Megatron Bridge, LiteLLM, Chroma, OpenAI Codex, and LM Studio, showing that enterprise AI tooling was a major attack surface at the event. Some attempts, including attacks against Oracle Autonomous AI Database and one OpenAI Codex entry, failed, but AI products still featured prominently as the competition’s enterprise-and-AI theme drove testing. After day one, DEVCORE Research Team led the standings with $205,000, and disclosed bugs now move into the contest’s 90-day vendor remediation window.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
12 events from the most recent confirmed update back to the earliest known activity.
After Pwn2Own Berlin 2026, the Microsoft Exchange remote code execution flaw CVE-2026-42897 demonstrated by Orange Tsai was reported as exploited in the wild and added to CISA's Known Exploited Vulnerabilities catalog. This marked an escalation from a contest-disclosed zero-day to an actively exploited vulnerability requiring operational response.
At the conclusion of Pwn2Own Berlin 2026, researchers had demonstrated 47 unique zero-day vulnerabilities and earned a total of $1,298,250. DEVCORE finished first with $505,000, followed by STARLabs SG with $242,500 and Out Of Bounds with $95,000, as the contest also recorded seven failed attempts.
On the final day of Pwn2Own Berlin 2026, STARLabs SG successfully exploited VMware ESXi and triggered the Cross-tenant Code Execution add-on. The demonstration earned $200,000 and 20 Master of Pwn points, making it the highest-value result reported for day three.
On the third and final day of Pwn2Own Berlin 2026, researchers added successful exploits against Red Hat Linux for Workstations and Windows 11. Sina Kheirkhah of Summoning Team earned a reduced award after a collision on one Red Hat bug, while Viettel Cyber Security won with a Windows 11 privilege-escalation exploit.
On the final day of Pwn2Own Berlin 2026, researcher splitline demonstrated a successful two-bug exploit chain against Microsoft SharePoint. The result contributed to DEVCORE securing the Master of Pwn title at the end of the competition.
On day two of Pwn2Own Berlin 2026, Orange Tsai of DEVCORE exploited Microsoft Exchange with an attack chain that achieved remote code execution and SYSTEM privileges. The demonstration earned $200,000 and was reported as the highest-value exploit of the competition at that point.
On the second day of Pwn2Own Berlin 2026, researchers earned $385,750 for 15 zero-day vulnerabilities against fully patched targets including Windows 11, Microsoft Exchange, Red Hat Enterprise Linux for Workstations, Cursor, and LiteLLM. The running competition total reached $908,750 for 39 unique vulnerabilities, while some attempts against Safari and SharePoint failed.
At the end of the first day, the DEVCORE Research Team led the competition leaderboard with $205,000 in winnings. Valentina Palmiotti was reported in second place with $70,000.
Researchers successfully compromised Windows 11 three separate times on day one using distinct local privilege escalation zero-days. The repeated successes highlighted Windows 11 as one of the most impacted targets of the opening day.
DEVCORE researcher Orange Tsai delivered the standout day-one exploit by chaining four logic bugs to escape the Microsoft Edge sandbox. The demonstration earned $175,000 and helped put DEVCORE in the lead.
On the first day of the competition, researchers earned a total of $523,000 for demonstrating 24 unique zero-day vulnerabilities across browsers, operating systems, AI platforms, and NVIDIA-related infrastructure. Successful targets included Microsoft Edge, Windows 11, Red Hat Linux for Workstations, NVIDIA Container Toolkit, NVIDIA Megatron Bridge, LiteLLM, OpenAI Codex, Chroma, and LM Studio.
Pwn2Own Berlin 2026 began at OffensiveCon as a three-day competition focused on enterprise and AI targets. The event was scheduled to run from 2026-05-14 through 2026-05-16 under rules requiring exploits against fully patched targets.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
13 references tracked. Mallory keeps watching after this page renders.
thecyberthrone.in
Open sourcesecurityaffairs.com
Open sourcecybersecuritynews.com
Open sourcezerodayinitiative.com
Open sourcezerodayinitiative.com
Open sourcebleepingcomputer.com
Open sourcezerodayinitiative.com
Open sourceopennet.me
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.