<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=10643465&amp;fmt=gif">

Pwn2Own Berlin Day 2: Microsoft Exchange Hit with $200K Zero-Day Exploit

Pwn2Own Berlin 2026 showcases dramatic hacks on enterprise software and AI tools, with $385,750 in bounties added and major vulnerabilities exposed.
Content Team

Day two of Pwn2Own Berlin 2026 saw hackers unleash devastating attacks on enterprise software and AI tools, adding $385,750 in bug bounties to bring the total to $908,750.

Orange Tsai from DEVCORE stole the show with a brutal Microsoft Exchange exploit, chaining three vulnerabilities to achieve remote code execution with SYSTEM privileges. The attack earned $200,000 and highlights Exchange's role as a critical enterprise target.

Security researchers also escalated privileges on Windows 11 through an integer overflow bug — worth $7,500, next to Exchange's $200,000 — and hit multiple AI coding platforms including Cursor IDE and OpenAI Codex. These AI tools are becoming prime targets due to their access to source code and developer workflows.

DEVCORE leads the competition on 40.5 Master of Pwn points and $405,000 in winnings, and the final day promises more zero-day discoveries. Every vendor now has 90 days to ship a fix before ZDI publishes the details.

Updated August 13, 2026: Pwn2Own Berlin closed on May 16 with $1,298,250 paid out for 47 zero-days, and DEVCORE took Master of Pwn on 50.5 points and $505,000.

Source: Cyber Security News

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo