16 Mai

Pwn2Own Berlin rakes in $908K for 39 zero-days across three days

Pwn2Own Berlin 2026 wraps up today at OffensiveCon, and the numbers are absurd. Over three days, researchers from around the world demonstrated 39 unique zero-day vulnerabilities and walked away with $908,750 in bounties. The event, organized by Trend Micro’s Zero Day Initiative, may have crossed the million-dollar mark by the time the final scores are tallied.

Day one set the tone. Windows 11 was breached three separate times. OrangeTsai pulled off a Microsoft Edge sandbox escape using four chained logic bugs, earning $175,000 in a single attempt. NVIDIA Container Toolkit and OpenAI Codex both got hit too. In total, day one produced 24 zero-days and $523,000 in payouts.

Here is the wild part: ZDI actually turned away researchers. For the first time in 19 years, organizers ran out of contest slots and had to reject dozens of working zero-day remote code execution submissions. The queue of exploits waiting to be demonstrated was longer than the event schedule allowed. That tells you something about both the volume of talent and the state of software security.

Day two was all about Microsoft Exchange. OrangeTsai returned with a three-vulnerability chain that achieved SYSTEM-level remote code execution on Exchange, earning $200,000. Forbes confirmed the exploit involves three previously unknown vulnerabilities chained together. The full technical details and a whitepaper were handed to ZDI immediately after the demo, which is the whole point of Pwn2Own: responsible disclosure with cash on the table instead of selling to the highest bidder on the grey market.

Day two also saw 15 more unique zero-days demonstrated, adding $385,750 to the pot. Windows 11 took more hits.

Day three is still unfolding, but early results show Summoning Team’s Sina Kheirkhah exploiting Red Hat Linux with a two-bug chain (one was a collision, but still earned $7,000). Viettel Cyber Security scored their fifth round win by using an integer overflow to escalate privileges on Windows 11, taking home $7,500. SharePoint and VMware ESXi remain on the target list as the final sessions play out.

Microsoft is going to be busy patching. Between the three Windows 11 zero-days from day one, the Exchange RCE from day two, and continued Windows 11 escalation exploits on day three, the company has a pile of CVEs to process. That is exactly how this is supposed to work: find the bugs before the bad guys do, get paid, hand over the details, let the vendor fix it.

The Master of Pwn title is still being decided. Check the ZDI blog for live standings.

Sources: ZDI Day Three Results, Forbes, Reddit r/cybersecurity, CyberSixt

Mots-cles

pwn2own zero-day cybersecurity microsoft windows 11