The first day of Pwn2Own Berlin 2026 confirmed once again why the competition is considered one of the most important events in the cybersecurity space. Security researchers from all over the world managed to exploit a total of 24 unique zero-day vulnerabilities, winning cash prizes that exceeded $523,000 in just a few hours.

This year's event, held as part of OffensiveCon in Berlin, focuses heavily on technologies artificial intelligence, cloud infrastructure, and enterprise software, reflecting the security industry's shift in interest towards AI tools and modern development environments.
The impressive attack on Microsoft Edge
The most interesting demonstration was by well-known researcher Orange Tsai, who managed to compromise Microsoft Edge using a chain of four different logic bugs. The attack led to a sandbox escape.
See also: CVE-2026-42897: Active Exchange Server vulnerability exploit
For this exploit, Orange Tsai received a total of $175,000, the largest reward of the event so far. This exploit is considered particularly important, as sandbox escape attacks remain among the most complex and dangerous techniques in the browser space.
Modern browsers rely on sandboxing mechanisms to isolate malicious code from the operating system. When a researcher manages to “break” this isolation, it demonstrates that an attacker could theoretically gain much broader control over a user’s device.

Windows 11 and Linux in the sights of researchers
Windows 11 was also a key focus of the competition. Angelboy and TwinkleStar03 from the DEVCORE internship program , along with Marcin Wiązowski and Kentaro Kawane from GMO Cybersecurity , demonstrated successful local privilege escalation attacks .
Each group received $30,000 for new zero-day exploits that allowed elevation of privilege in Microsoft's operating system. Attacks of this type are particularly critical, as they can turn limited user access into complete system control.
Meanwhile, Valentina Palmiotti from IBM X-Force Offensive Research managed to gain root access to Red Hat Linux for Workstations, earning $20,000. The same researcher also impressed with a zero-day exploit in the NVIDIA Container Toolkit, adding another $50,000 to her total earnings.
The fact that Linux environments and container tools were at the center of Pwn2Own shows how important the security of cloud-native infrastructures and AI clusters has become
See also: New vulnerability in PraisonAI: Targeted a few hours after disclosure
Artificial intelligence takes center stage in hacking
One of the most interesting elements of this year's event is the strong presence of AI tools and large language models among the researchers' goals.
Compass Security and Doyensec's maitai managed to breach OpenAI's Codex, earning $40,000 each. Successful attacks were recorded on LiteLLM, NVIDIA Megatron Bridge, Chroma, and LM Studio.

The presence of these tools at Pwn2Own reveals that AI application security is now a top priority for the industry. Until a few years ago, hacking competitions focused mainly on browsers, hypervisors and operating systems. However, today, LLMs, inference tools and AI platforms are being treated as critical attack surfaces.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Experts warn that AI tools have enormous potential to access data, repositories, API keys and corporate infrastructure, which makes them an attractive target for cybercriminals.
DEVCORE leads the competition
After the completion of the first day, DEVCORE is at the top of the leaderboard with total winnings of $205,000, followed by Valentina Palmiotti with $70,000.
The next few days are expected to be even more intense, as participants will attempt to exploit zero-days in Microsoft SharePoint, Exchange Server, Safari, Firefox, Anthropic's Claude Code, and other enterprise platforms.
See also: NGINX Rift: Critical 18-year-old vulnerability allows RCE without authentication

According to Pwn2Own's rules, all targets are running fully updated software versions, which means that attacks rely solely on previously unknown vulnerabilities.
After the flaws are disclosed, manufacturers have 90 days to release security patches. This process is considered critical to the cybersecurity ecosystem, as it allows for the identification of serious weaknesses before they are exploited by real attackers.
Source: www.bleepingcomputer.com
