The world of enterprise security was shaken on the second day of Pwn2Own Berlin 2026, as top hackers successfully exploited a range of fully patched, critical software, including Microsoft Exchange, Windows 11, and Red Hat Enterprise Linux. The competition, which focuses on enterprise technologies and artificial intelligence, saw competitors collect $385,750 for demonstrating 15 unique zero-day vulnerabilities.
What Happened
During Pwn2Own Berlin 2026, held at the OffensiveCon conference, security researchers target fully updated products across various categories. A key rule mandates that all entries must compromise the target and demonstrate arbitrary code execution. Once vulnerabilities are disclosed, vendors are given 90 days to release patches.
The second day brought a series of high-impact disclosures:
- Microsoft Exchange Remote Code Execution: Cheng-Da Tsai, known as Orange Tsai, from the DEVCORE Research Team, was the top earner on day two. He secured a massive $200,000 prize by chaining three distinct bugs to achieve remote code execution (RCE) with SYSTEM privileges on Microsoft Exchange. This is a critical blow given Exchange's widespread use in enterprise environments.
- Windows 11 Exploits: Siyeon Wi successfully hacked Windows 11 by exploiting an integer overflow bug, earning $7,500. This builds on Day One's activity where Windows 11 was targeted three times by researchers like Angelboy and TwinkleStar03 (DEVCORE Internship Program), Kentaro Kawane (GMO Cybersecurity), and Marcin Wiązowski, each demonstrating new privilege-escalation zero-days and collecting $30,000 apiece.
- Red Hat Enterprise Linux (RHEL) Privilege Escalation: Ben Koo of Team DDOS escalated privileges to root on Red Hat Enterprise Linux for Workstations, securing a $10,000 cash prize. On day one, Valentina Palmiotti (chompie) of IBM X-Force Offensive Research also rooted RHEL for Workstations, earning $20,000.
- NVIDIA Container Toolkit: The NVIDIA Container Toolkit was exploited by 0xDACA and Noam Trobishi using a use-after-free bug. Valentina Palmiotti also exploited this toolkit on day one for a $50,000 prize.
- AI Category Exploits: Reflecting the competition's focus on artificial intelligence, several AI platforms were targeted. Le Duc Anh Vu of Viettel Cyber Security successfully hacked the Cursor AI coding agent for $30,000. Sina Kheirkhah of Summoning Team demonstrated a zero-day in OpenAI Codex, earning $20,000, and Compass Security also exploited Cursor for $15,000.
These exploits follow a dynamic first day where Orange Tsai also earned $175,000 for a Microsoft Edge sandbox escape by chaining four logic bugs.
Why It Matters
Pwn2Own serves as a crucial platform for identifying critical vulnerabilities before they can be widely exploited by malicious actors. For developers and IT professionals, these disclosures underscore several key points:
- Continuous Security Posture: Even widely deployed and seemingly hardened enterprise software like Microsoft Exchange and Windows 11 remain susceptible to complex, chained zero-day attacks. This highlights the constant need for vigilance, robust patch management, and defense-in-depth strategies.
- Impact of Zero-Days: Remote Code Execution (RCE) with SYSTEM privileges on Exchange is particularly concerning, as it could grant attackers complete control over email servers, leading to data breaches, ransomware attacks, and widespread organizational disruption. Privilege escalation on operating systems like Windows and RHEL allows attackers to gain full control over compromised systems, making post-exploitation activities much easier.
- Emerging AI Security Risks: The successful exploitation of AI coding agents like Cursor AI and OpenAI Codex is a significant development. As AI tools become more integrated into development workflows and critical systems, their security vulnerabilities pose new risks. Developers leveraging these tools must be aware of potential attack vectors and ensure their usage adheres to security best practices. This also signals a burgeoning field for security research focused on AI's unique challenges.
- Vendor Responsibility and Patching: The 90-day disclosure policy mandates vendors to respond swiftly. While this gives them a window to develop and deploy fixes, IT teams must be prepared to apply these patches promptly as soon as they are available.
What To Watch
As Pwn2Own Berlin 2026 continues, the third day is set to target additional high-value products, including Microsoft Windows 11, VMware ESXi, Red Hat Enterprise Linux, Microsoft SharePoint, and more AI coding agents. The sustained focus on enterprise and AI solutions indicates a broader industry trend where the attack surface is expanding and diversifying.
Organizations should monitor official vendor security advisories closely for the patches addressing these newly disclosed zero-days. For developers working with AI platforms, the Pwn2Own results are a clear signal to prioritize security in their AI development and integration, understanding that these tools are not immune to sophisticated attacks. The ongoing discoveries at events like Pwn2Own reinforce the critical role of the cybersecurity community in securing the digital landscape.
The full schedule and detailed results are available on the ZDI (Zero Day Initiative) website, the organizer of Pwn2Own.