Pwn2Own Berlin 2026: 47 Zero-Days Exploited, $1.3M Awarded
Monitor Windows 11, Exchange, and AI agents for the 47 zero‑day vulnerabilities and apply vendor patches promptly.
Monitor Windows 11, Exchange, and AI agents for the 47 zero‑day vulnerabilities and apply vendor patches promptly.
Summary
The Pwn2Own Berlin 2026 contest concluded with participants exploiting 47 zero‑day flaws and earning $1,298,250 in rewards.
The competition ran from May 14 to 16 at OffensiveCon and focused on enterprise technologies, AI, and container environments. DEVCORE topped the leaderboard with 50.5 Master of Pwn points, earning $505,000 after hacking Microsoft SharePoint, Exchange, Edge, and Windows 11. Orange Tsai chained three bugs for remote code execution with SYSTEM privileges on Exchange, earning $200,000, while other teams exploited Windows 11, Red Hat Enterprise Linux, and AI coding agents such as Cursor and OpenAI Codex.
Each vendor has 90 days to release patches before TrendMicro’s Zero Day Initiative publicly discloses the flaws. The event highlighted the continued prevalence of privilege‑escalation and sandbox‑escape vulnerabilities in widely used software. The competition also showcased new AI‑related zero‑days, underscoring the need for robust AI security testing. Participants demonstrated that even fully patched systems can be compromised if security controls are insufficient. The results emphasize the importance of rapid patch management and threat intelligence for enterprise customers.
Key changes
- 47 zero‑day flaws were exploited during Pwn2Own Berlin 2026.
- Participants earned $1,298,250 in rewards.
- DEVCORE topped the leaderboard with 50.5 points.
- Orange Tsai chained three bugs for RCE on Exchange.
- Windows 11 was hacked three times on day one.
- AI agents such as Cursor and OpenAI Codex were exploited.
- Vendors have 90 days to patch before public disclosure.
- The event highlighted privilege‑escalation and sandbox‑escape bugs.