# Pwn2Own Berlin 2026: Second Day Yields 15 Zero-Day Vulnerabilities in Critical Enterprise Systems
The second day of Pwn2Own Berlin 2026 delivered a stunning demonstration of vulnerabilities across the enterprise technology stack. On May 15, security researchers claimed $385,750 in cash awards after exposing 15 unique zero-day flaws in Windows 11, Microsoft Exchange, Red Hat Enterprise Linux, NVIDIA Container Toolkit, and AI coding agents—underscoring the breadth of security gaps in systems organizations depend on daily.
## The Threat: Critical Systems Fall Across Multiple Fronts
Over the course of a single day, competitors successfully demonstrated remote code execution, privilege escalation, and sandbox escape vulnerabilities in some of the world's most widely deployed software. The exploits ranged from sophisticated multi-bug chains requiring deep technical knowledge to single-vulnerability attacks that exposed fundamental design flaws.
Key exploits demonstrated on Day 2 included:
| Target | Vulnerability Type | Researcher(s) | Award |
|--------|-------------------|---------------|----|
| Microsoft Exchange | Multi-bug chain (3 flaws) | Orange Tsai (DEVCORE) | $200,000 |
| Windows 11 | Integer overflow | Siyeon Wi | $7,500 |
| Red Hat Enterprise Linux Workstations | Privilege escalation to root | Ben Koo (Team DDOS) | $10,000 |
| NVIDIA Container Toolkit | Use-after-free bug | 0xDACA & Noam Trobinski | $12,500 |
| Cursor AI Coding Agent | Logic/execution flaw | Le Duc Anh Vu (Viettel Cyber Security) | $30,000 |
| Cursor AI (second exploit) | Design vulnerability | Compass Security | $15,000 |
| OpenAI Codex | Zero-day exploitation | Sina Kheirkhah (Summoning Team) | $20,000 |
The standout achievement came from Orange Tsai, who chained three separate bugs together to gain SYSTEM-level remote code execution on Microsoft Exchange—a particularly concerning vulnerability given Exchange's role as the backbone of enterprise email infrastructure. This exploit demonstrates that defenders cannot rely on patching single issues; sophisticated attackers can combine multiple flaws to bypass existing security controls.
## Background and Context: Understanding Pwn2Own
Pwn2Own Berlin 2026 is a controlled hacking competition organized by Trend Micro's Zero Day Initiative (ZDI) and held at the OffensiveCon conference (May 14-16, 2026). It serves a critical function in the security ecosystem: it incentivizes responsible disclosure of zero-day vulnerabilities before they can be weaponized by malicious actors.
The competition structure is straightforward but demanding:
This year's event focuses heavily on enterprise technologies and artificial intelligence—a significant shift reflecting the security community's growing concern about AI systems as attack surfaces.
Pwn2Own's historical impact: In last year's Berlin competition (2025), researchers claimed approximately $1.08 million across 29 zero-day vulnerabilities. These disclosures systematically move critical flaws from the hands of potential adversaries into vendor patch labs.
## Technical Details: The Nature of the Exploits
The vulnerabilities demonstrated on Day 2 reveal troubling patterns in how modern software fails under adversarial conditions.
### Multi-Bug Exploitation (The Exchange Attack)
Orange Tsai's Exchange exploit is instructive. By chaining three separate logic bugs, Tsai was able to:
1. Bypass initial authentication or access controls
2. Escalate permissions in the context of the Exchange server
3. Achieve execution with SYSTEM privileges (the highest level of access on Windows)
This approach underscores a critical weakness: when multiple functions have independent flaws, an attacker can leverage them sequentially to reach objectives that individual patches might prevent. The 90-day patch window means this specific chain of flaws is known to vendors but potentially exploitable by others who independently discover the same issues.
### Privilege Escalation in Linux
Red Hat Enterprise Linux and NVIDIA Container Toolkit both fell to privilege escalation attacks—flaws that allow unprivileged users to gain root access. Container environments are particularly concerning targets because:
### The Emerging AI Attack Surface
The AI and coding agent exploits (Cursor, OpenAI Codex) represent a new and under-protected attack surface. These tools are increasingly integrated into developer workflows and often have access to:
Compromising a coding agent could yield access to sensitive intellectual property or credentials across entire organizations.
## Implications: A 90-Day Vulnerability Window
The disclosure of 15 zero-day vulnerabilities creates an immediate implications timeline:
Immediate (Days 1-7):
Short-term (Weeks 2-12):
Critical Window (Days 1-90):
The implications are severe for organizations running unpatched systems. Microsoft Exchange servers in particular are high-value targets for both espionage and ransomware operations. A SYSTEM-level RCE on Exchange could yield:
## Recommendations for Organizations
Organizations should prioritize immediate action in this order:
1. Inventory Critical Systems (This Week)
2. Monitor Vendor Advisories (Ongoing)
3. Implement Compensating Controls (Immediate)
4. Test Patches in Non-Production (Before Deployment)
---
## HackWire Analysis
Pwn2Own Berlin 2026 exposes three uncomfortable truths about the current security landscape that deserve deeper examination.
First, the diversity of targets reveals that we've failed to "move left" on security. Microsoft Exchange, Windows 11, and NVIDIA Container Toolkit are not bleeding-edge research projects—they're mature, heavily audited enterprise products that have existed for years. Yet Day 2 alone yielded 15 independent ways to compromise them. This isn't a sign of particularly clever researchers (though they are clever); it's evidence that traditional security testing, code review, and fuzzing are insufficient for large, complex codebases. Organizations cannot rely on vendors to find every flaw before release.
Second, the shift to AI/coding agent exploits represents a new vulnerability class we're still learning to defend against. Cursor and OpenAI Codex are relatively recent products serving developer workflows. They were never designed with the same adversarial threat model as operating systems or databases. Yet researchers compromised them almost casually—$30,000 to $50,000 per exploit is trivial relative to the potential value of accessing developer credentials and source code. As AI tools become more central to enterprise workflows, the attack surface expands exponentially. Organizations deploying these tools should assume they will face targeted attacks and implement strict credential isolation and network segmentation.
Third, the 90-day patch window is no longer acceptable. In 2026, sophisticated attackers can independently rediscover vulnerabilities disclosed at conferences within weeks. The 90-day timeline works well for research partnerships but fails organizations under active threat. The real challenge isn't patching—it's the gap between when a vulnerability becomes known to security researchers and when it becomes known to operational security teams. Organizations need to shift from "react to patches when they arrive" to "assume these vulnerabilities are exploitable starting today."
The most dangerous implication: defenders are now in a reactive posture against a very credible threat. Security teams at organizations running Exchange, Windows 11, and containerized infrastructure should assume they are already targeted by actors who have independently discovered similar chains of flaws. The next 90 days will determine which organizations survive this disclosure cycle and which become breaches.
— HackWire Editorial
---
## Related Coverage