This year’s Pwn2Own Berlin 2026 cybersecurity competition concluded with impressive results, confirming once again that zero-day vulnerabilities remain one of the most significant problems in the technology industry. In just three days, top security researchers managed to exploit a total of 47 unknown security vulnerabilities , winning cash prizes worth $1,298,250.

The event took place as part of the OffensiveCon in Berlin, from May 14 to 16, and focused mainly on enterprise technologies, cloud infrastructure, virtualization platforms and artificial intelligence tools. This year's event is considered one of the most demanding in the history of Pwn2Own, as participants targeted fully updated systems and modern AI platforms already used in business environments.
The biggest goals of the Pwn2Own Berlin 2026
During Pwn2Own Berlin 2026, security teams attacked a wide range of technologies, demonstrating how extensive the attack surface in the modern digital world.
See also: VMware Fusion: Vulnerability allows privilege escalation
The targets included web browsers, enterprise applications, virtualization platforms, container environments, cloud-native infrastructures, operating systems, and large AI language models. The categories involving AI inference engines and LLM frameworks, as this was the first time such a large number of successful exploits were recorded in AI-related technologies.
The competition organizers had already warned that artificial intelligence is now becoming a key target for attackers, as more and more businesses integrate autonomous AI tools into critical infrastructure.
Over half a million dollars on the first day
The first day of the competition proved to be extremely productive for security researchers. A total of $523,000 was awarded for 24 unique zero-day exploits that primarily targeted Microsoft products, Linux environments, and AI frameworks.
The second day added another $385,750 to the total, as 15 additional zero-days. The attacks focused primarily on privilege escalation flaws, root exploits, and vulnerabilities in enterprise AI infrastructure.
On the third and final day of the event, participants won another $389,500 for eight new vulnerabilities, bringing the final total to $1,298,250.
See also: WordPress: Hackers exploit Burst Statistics vulnerability
The total result significantly surpassed last year's Pwn2Own Berlin, where approximately $1.07 million was awarded for 29 zero-days.

DEVCORE dominated Pwn2Own Berlin 2026
The big winner of the event was DEVCORE, who won the title of “Master of Pwn” by collecting 50.5 points and a total of $505,000 in rewards.
The team successfully compromised critical Microsoft technologies, including Microsoft Exchange, SharePoint, Edge, and Windows 11.
In second place was STARLabs SG with $242,500 and 25 points, while third place was won by the Out Of Bounds with $95,750.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The top prize of this year's competition went to well-known researcher Cheng-Da Tsai, better known as Orange Tsai, a member of DEVCORE. Tsai won $200,000 after he managed to combine three different vulnerabilities to gain remote code execution with SYSTEM privileges in Microsoft Exchange. He also won $175,000 for a Microsoft Edge sandbox escape chain that combined four logic bugs.
Windows 11, Linux and VMware at the center of attacks
Windows 11 was one of the main targets of this year's competition. During the three-day event, multiple exploits were presented that allowed local privilege escalation, sandbox escapes, and security breaches.
Particularly impressive was the demonstration of the Edge sandbox escape chain by Orange Tsai, who exploited four logic bugs to bypass the browser's security isolation.
See also: CVE-2026-42897: Active Exchange Server vulnerability exploit
At the same time, Red Hat Enterprise Linux for Workstations suffered several successful root privilege escalation, while zero-days affecting the NVIDIA Container Toolkit were also reported.
On the final day of the competition, researchers also managed to exploit a memory corruption vulnerability in VMware ESXi, highlighting that virtualization platforms continue to be high-value targets for attackers.

The new era of AI exploits
One of the most important findings of this year's Pwn2Own is the rapid increase in attacks on AI systems. Researchers presented multiple zero-days in AI coding agents and inference platforms, confirming that artificial intelligence is now evolving into a critical security challenge.
As businesses increasingly adopt autonomous AI tools for software development, data management, and cloud operations, the potential for abuse of such systems increases dramatically.
Experts warn that AI platforms have access to API keys, credentials, and internal infrastructure, meaning a successful exploit can have devastating consequences.
See also: New vulnerability in PraisonAI: Targeted a few hours after disclosure

Companies now have 90 days to correct
After the completion of Pwn2Own, companies affected by zero-days have 90 days to release security patches before Trend Micro's Zero Day Initiative publicly discloses the technical details of the vulnerabilities.
This process is considered particularly important for the protection of millions of users worldwide, as it gives vendors time to address problems before the information becomes publicly available.
Pwn2Own Berlin 2026 proved once again that cybersecurity is evolving at a faster pace than ever and that even the most modern systems remain vulnerable to well-organized researchers and attackers.
Source: www.bleepingcomputer.com
