Hackers at Pwn2Own earned $385,000 for new zero-day exploits

The second day of the Pwn2Own Berlin 2026 competition brought 15 new zero-day vulnerabilities across Microsoft Exchange, Windows 11, Red Hat Enterprise Linux and AI tools. The top reward went to researcher Orange Tsai for a chain of bugs leading to remote code execution on Microsoft Exchange.
The second day of Pwn2Own Berlin 2026 saw security researchers take home a total of $385,750 in rewards for successful demonstrations of 15 unique zero-day vulnerabilities. Among the affected products were, among others, Microsoft Exchange, Windows 11, Red Hat Enterprise Linux and NVIDIA Container Toolkit. The highest reward was won by renowned researcher Orange Tsai from the DEVCORE team.
Orange Tsai won $200,000 for compromising Microsoft Exchange
Cheng-Da Tsai, known by the nickname Orange Tsai and working with the DEVCORE Research Team, received $200,000 for a chain of three vulnerabilities leading to remote code execution (RCE) with SYSTEM privileges on Microsoft Exchange. It was also the highest single payout of this year's competition.
Researcher Siyeon Wi received $7,500 for exploiting an integer overflow bug in Windows 11. Ben Koo from Team DDOS earned $10,000 for a local privilege escalation to user root on Red Hat Enterprise Linux for Workstations. Researchers 0xDACA and Noam Trobishi subsequently succeeded in exploiting a use-after-free bug in the NVIDIA Container Toolkit.
AI tools were one of the main targets of the competition
A significant portion of the second day also consisted of attacks on AI tools and developer assistants. Le Duc Anh Vu from Viettel Cyber Security received $30,000 for compromising the AI assistant Cursor. Sina Kheirkhah from Summoning Team demonstrated a zero-day exploit in OpenAI Codex and earned $20,000. Another successful attack on Cursor was later demonstrated by the Compass Security team for a reward of $15,000.
Pwn2Own Berlin 2026 takes place from May 14–16 as part of the OffensiveCon conference in Berlin and focuses mainly on enterprise technologies, virtualization, cloud-native environments and artificial intelligence. Overall, researchers can win more than $1 million in rewards. The competition requires successfully compromising fully patched systems and demonstrating code execution or another defined form of compromise. Vendors then have 90 days to release security fixes.
Windows 11, Exchange and Linux under pressure
The second day of the competition brought several attacks on enterprise infrastructure and operating systems. Besides the successful RCE attack on Microsoft Exchange, other local privilege escalations were demonstrated on Windows 11 and Red Hat Enterprise Linux. In the case of the NVIDIA Container Toolkit, it was a use-after-free bug that allowed compromise of the container environment.
After two days of the competition, the total amount of rewards paid reached $908,750 for 39 unique zero-day vulnerabilities. Team DEVCORE, thanks to Orange Tsai's performance, leads the running Master of Pwn standings.
The third day targets Windows 11, ESXi or SharePoint
For the third day of the competition, organizers planned further attempts targeting, for example, Microsoft Windows 11, VMware ESXi, Microsoft SharePoint, Red Hat Enterprise Linux and several AI agents for code generation. The initiative Zero Day Initiative (ZDI) publishes the complete results on its website as they become available.