# Pwn2Own Berlin 2026: Second Day Yields 15 Zero-Day Vulnerabilities in Critical Enterprise Systems


The second day of Pwn2Own Berlin 2026 delivered a stunning demonstration of vulnerabilities across the enterprise technology stack. On May 15, security researchers claimed $385,750 in cash awards after exposing 15 unique zero-day flaws in Windows 11, Microsoft Exchange, Red Hat Enterprise Linux, NVIDIA Container Toolkit, and AI coding agents—underscoring the breadth of security gaps in systems organizations depend on daily.


## The Threat: Critical Systems Fall Across Multiple Fronts


Over the course of a single day, competitors successfully demonstrated remote code execution, privilege escalation, and sandbox escape vulnerabilities in some of the world's most widely deployed software. The exploits ranged from sophisticated multi-bug chains requiring deep technical knowledge to single-vulnerability attacks that exposed fundamental design flaws.


Key exploits demonstrated on Day 2 included:


| Target | Vulnerability Type | Researcher(s) | Award |

|--------|-------------------|---------------|----|

| Microsoft Exchange | Multi-bug chain (3 flaws) | Orange Tsai (DEVCORE) | $200,000 |

| Windows 11 | Integer overflow | Siyeon Wi | $7,500 |

| Red Hat Enterprise Linux Workstations | Privilege escalation to root | Ben Koo (Team DDOS) | $10,000 |

| NVIDIA Container Toolkit | Use-after-free bug | 0xDACA & Noam Trobinski | $12,500 |

| Cursor AI Coding Agent | Logic/execution flaw | Le Duc Anh Vu (Viettel Cyber Security) | $30,000 |

| Cursor AI (second exploit) | Design vulnerability | Compass Security | $15,000 |

| OpenAI Codex | Zero-day exploitation | Sina Kheirkhah (Summoning Team) | $20,000 |


The standout achievement came from Orange Tsai, who chained three separate bugs together to gain SYSTEM-level remote code execution on Microsoft Exchange—a particularly concerning vulnerability given Exchange's role as the backbone of enterprise email infrastructure. This exploit demonstrates that defenders cannot rely on patching single issues; sophisticated attackers can combine multiple flaws to bypass existing security controls.


## Background and Context: Understanding Pwn2Own


Pwn2Own Berlin 2026 is a controlled hacking competition organized by Trend Micro's Zero Day Initiative (ZDI) and held at the OffensiveCon conference (May 14-16, 2026). It serves a critical function in the security ecosystem: it incentivizes responsible disclosure of zero-day vulnerabilities before they can be weaponized by malicious actors.


The competition structure is straightforward but demanding:

  • All targeted devices run fully patched latest versions of their operating systems
  • Researchers must demonstrate arbitrary code execution to win awards
  • Vendors receive the vulnerability details under embargo and have 90 days to develop and release patches
  • Total prize pool exceeds $1 million across all three days

  • This year's event focuses heavily on enterprise technologies and artificial intelligence—a significant shift reflecting the security community's growing concern about AI systems as attack surfaces.


    Pwn2Own's historical impact: In last year's Berlin competition (2025), researchers claimed approximately $1.08 million across 29 zero-day vulnerabilities. These disclosures systematically move critical flaws from the hands of potential adversaries into vendor patch labs.


    ## Technical Details: The Nature of the Exploits


    The vulnerabilities demonstrated on Day 2 reveal troubling patterns in how modern software fails under adversarial conditions.


    ### Multi-Bug Exploitation (The Exchange Attack)


    Orange Tsai's Exchange exploit is instructive. By chaining three separate logic bugs, Tsai was able to:

    1. Bypass initial authentication or access controls

    2. Escalate permissions in the context of the Exchange server

    3. Achieve execution with SYSTEM privileges (the highest level of access on Windows)


    This approach underscores a critical weakness: when multiple functions have independent flaws, an attacker can leverage them sequentially to reach objectives that individual patches might prevent. The 90-day patch window means this specific chain of flaws is known to vendors but potentially exploitable by others who independently discover the same issues.


    ### Privilege Escalation in Linux


    Red Hat Enterprise Linux and NVIDIA Container Toolkit both fell to privilege escalation attacks—flaws that allow unprivileged users to gain root access. Container environments are particularly concerning targets because:

  • A compromised container can potentially break out to affect the host system
  • Container orchestration platforms (Kubernetes, Docker Compose) often run with elevated privileges
  • Privilege escalation vulnerabilities can cascade through containerized infrastructure

  • ### The Emerging AI Attack Surface


    The AI and coding agent exploits (Cursor, OpenAI Codex) represent a new and under-protected attack surface. These tools are increasingly integrated into developer workflows and often have access to:

  • Source code repositories
  • API keys and credentials
  • Development environment secrets
  • Customer data processed during code analysis

  • Compromising a coding agent could yield access to sensitive intellectual property or credentials across entire organizations.


    ## Implications: A 90-Day Vulnerability Window


    The disclosure of 15 zero-day vulnerabilities creates an immediate implications timeline:


    Immediate (Days 1-7):

  • Microsoft, Red Hat, NVIDIA, and AI vendors receive detailed exploit information
  • These companies begin emergency patch development
  • Organizations cannot yet patch—the vulnerabilities are not public

  • Short-term (Weeks 2-12):

  • Vendors release patches as they complete testing
  • Organizations must prioritize patching Exchange and Windows 11 immediately
  • Adversaries may discover the same vulnerabilities independently or through leaked information

  • Critical Window (Days 1-90):

  • Organizations have 90 days from disclosure to patch before details become fully public
  • Any organization not patching within this window faces elevated exploitation risk
  • Zero-day brokers and nation-states may have already discovered similar flaws

  • The implications are severe for organizations running unpatched systems. Microsoft Exchange servers in particular are high-value targets for both espionage and ransomware operations. A SYSTEM-level RCE on Exchange could yield:

  • Complete email interception
  • Access to organization-wide shared mailboxes
  • Potential lateral movement to on-premises and cloud infrastructure
  • Credential harvesting from stored authentication tokens

  • ## Recommendations for Organizations


    Organizations should prioritize immediate action in this order:


    1. Inventory Critical Systems (This Week)

  • Identify all Microsoft Exchange servers and Windows 11 deployments
  • Document NVIDIA Container Toolkit usage in container environments
  • Catalog any deployment of Cursor, OpenAI Codex, or similar AI coding agents

  • 2. Monitor Vendor Advisories (Ongoing)

  • Subscribe to Microsoft Security Updates, Red Hat Security Advisories, and NVIDIA Security Bulletins
  • Establish a patch deployment schedule prioritizing Exchange and Windows 11
  • Expect patches to be released over the next 30-60 days

  • 3. Implement Compensating Controls (Immediate)

  • Restrict Exchange access to required networks using firewall rules
  • Enable advanced threat protection and anomaly detection on Exchange servers
  • Isolate container environments and monitor for privilege escalation attempts
  • Audit access logs for suspicious authentication patterns

  • 4. Test Patches in Non-Production (Before Deployment)

  • Vendors will release patches over time; test each in isolated environments
  • Exchange patches in particular should be validated thoroughly before production deployment

  • ---


    ## HackWire Analysis


    Pwn2Own Berlin 2026 exposes three uncomfortable truths about the current security landscape that deserve deeper examination.


    First, the diversity of targets reveals that we've failed to "move left" on security. Microsoft Exchange, Windows 11, and NVIDIA Container Toolkit are not bleeding-edge research projects—they're mature, heavily audited enterprise products that have existed for years. Yet Day 2 alone yielded 15 independent ways to compromise them. This isn't a sign of particularly clever researchers (though they are clever); it's evidence that traditional security testing, code review, and fuzzing are insufficient for large, complex codebases. Organizations cannot rely on vendors to find every flaw before release.


    Second, the shift to AI/coding agent exploits represents a new vulnerability class we're still learning to defend against. Cursor and OpenAI Codex are relatively recent products serving developer workflows. They were never designed with the same adversarial threat model as operating systems or databases. Yet researchers compromised them almost casually—$30,000 to $50,000 per exploit is trivial relative to the potential value of accessing developer credentials and source code. As AI tools become more central to enterprise workflows, the attack surface expands exponentially. Organizations deploying these tools should assume they will face targeted attacks and implement strict credential isolation and network segmentation.


    Third, the 90-day patch window is no longer acceptable. In 2026, sophisticated attackers can independently rediscover vulnerabilities disclosed at conferences within weeks. The 90-day timeline works well for research partnerships but fails organizations under active threat. The real challenge isn't patching—it's the gap between when a vulnerability becomes known to security researchers and when it becomes known to operational security teams. Organizations need to shift from "react to patches when they arrive" to "assume these vulnerabilities are exploitable starting today."


    The most dangerous implication: defenders are now in a reactive posture against a very credible threat. Security teams at organizations running Exchange, Windows 11, and containerized infrastructure should assume they are already targeted by actors who have independently discovered similar chains of flaws. The next 90 days will determine which organizations survive this disclosure cycle and which become breaches.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)