What Happened at Pwn2Own Berlin 2026?

A Windows 11 security zero-day exploit made headlines when elite researchers took the stage at Pwn2Own Berlin 2026 and successfully compromised Microsoft’s flagship operating system โ not once, but multiple times across the event. Day two of the competition, held on 15 May 2026, proved to be one of the most dramatic single days in the contest’s history, with competitors walking away with $385,750 in cash awards after demonstrating 15 unique zero-day vulnerabilities. Combined with day one’s $523,000 haul, the two-day running total hit $908,750 across 39 unique vulnerabilities.
The event, organised by Trend Micro’s Zero Day Initiative (ZDI), gathers some of the world’s sharpest offensive security researchers and challenges them to exploit fully patched, enterprise-grade software. The results are reported responsibly to vendors, who then race to issue patches before details go public โ typically within 90 days under ZDI’s disclosure policy.
The Microsoft Exchange Zero-Day: The Single Biggest Hit
The standout moment of day two was DEVCORE’s successful exploitation of Microsoft Exchange, which earned them the single largest payout of the entire contest: $200,000. The team chained together multiple vulnerabilities to achieve remote code execution on a fully patched Exchange server โ an alarming result for the millions of organisations that rely on Exchange for business-critical email infrastructure.
Microsoft Exchange has long been a high-value target for threat actors โ the 2021 ProxyLogon and ProxyShell campaigns demonstrated just how devastating Exchange exploits can be in the wild. The Pwn2Own demonstration is a controlled, responsible disclosure environment, but it serves as a stark reminder that even the most widely deployed enterprise mail server still harbours exploitable attack surfaces.
Why Exchange Exploits Are So Dangerous
-
Email is the gateway: A compromised Exchange server can expose every email, calendar entry, and contact in an organisation.
-
Active Directory integration: Exchange is tightly coupled with Active Directory, meaning a server compromise can escalate rapidly to domain-level access.
-
Internet-facing by design: Many Exchange deployments expose HTTPS endpoints directly to the internet, making remote exploitation scenarios realistic.
-
Slow patching cycles: Large organisations often delay Exchange patches due to complexity, leaving a wide window of exposure.
How Windows 11 Was Exploited on Day Two

Windows 11 exploit techniques demonstrated at Pwn2Own Berlin 2026 targeted the OS both as a standalone target and as part of chained attack sequences. Across days one and two of the competition, Windows 11 was successfully compromised at least three times within 24 hours, according to reporting by Forbes. Techniques included privilege escalation chains and logic flaw exploits โ categories that are notoriously difficult to defend against with standard security tooling because they abuse legitimate OS behaviour rather than memory corruption.
Notably, Orange Tsai โ one of the most respected names in offensive security research โ demonstrated a chain of four logic flaws to achieve exploitation. Logic bugs don’t trigger conventional exploit mitigations like ASLR or DEP, which is part of what makes them so valuable to researchers and so troubling for defenders.
Types of Windows Zero-Day Vulnerability Demonstrated
-
Privilege escalation: Attackers gain higher system permissions than they are authorised to hold, enabling them to install malware, disable security tools, or pivot to other systems.
-
Logic flaw chains: Multiple individually low-severity design issues are combined to produce a high-impact outcome with no memory corruption involved.
-
Kernel-level exploits: Some attacks targeted Windows at the kernel layer, the deepest level of the OS, bypassing user-mode security controls entirely.
Red Hat Enterprise Linux and Cursor Also Fell
Windows wasn’t the only victim on day two. Red Hat Enterprise Linux was also successfully exploited, reinforcing that zero-day risk is not a Windows-exclusive problem. The AI code editor Cursor was also targeted, reflecting a growing trend at Pwn2Own: as AI development tools become part of everyday enterprise workflows, they are increasingly considered legitimate attack surfaces. With 47 total zero-days uncovered across the full Pwn2Own Berlin 2026 event, no vendor escaped entirely unscathed.
What Is Zero-Day Disclosure and How Does the Patch Timeline Work?

Understanding how a zero-day exploit Windows researchers discover at a competition moves from demonstration to patch is important for planning your own security response.
-
Day of exploit: The researcher demonstrates the vulnerability live. ZDI captures all technical details privately.
-
Vendor notification: ZDI notifies Microsoft (or the relevant vendor) immediately after the competition. The clock starts.
-
90-day disclosure window: ZDI’s policy gives vendors 90 days to issue a patch. If no patch arrives, ZDI publishes limited technical details to incentivise action.
-
Patch Tuesday integration: Microsoft typically targets the next available Patch Tuesday (the second Tuesday of each month) to ship fixes for responsibly disclosed vulnerabilities.
-
Public CVE assignment: Once patched, a Common Vulnerabilities and Exposures (CVE) identifier is published so organisations can track remediation.
Given that Pwn2Own Berlin 2026 concluded in mid-May 2026, the June and July 2026 Patch Tuesday updates are the most likely delivery vehicles for fixes addressing these specific Windows 11 security zero-day exploit disclosures. The May 2026 security update had already shipped before the event began โ and ZDI’s own blog noted that vendors typically try to clear as many issues as possible before Pwn2Own starts.
Should You Be Worried Right Now?
The short answer: be alert, not alarmed. Pwn2Own zero-day exploit Windows vulnerabilities are disclosed responsibly and are not published for public use. Real-world threat actors cannot simply download a working exploit the day after a Pwn2Own demonstration. However, there is a meaningful risk window between the date of disclosure and the date a patch ships and is deployed across your fleet. During that window, nation-state actors and well-resourced criminal groups have historically reverse-engineered patches to develop their own exploits โ so the time between “patch released” and “patch applied” matters enormously.
Immediate Steps to Reduce Your Exposure
-
Apply Windows updates immediately. Every pending update should be treated as a priority. Don’t delay Patch Tuesday cycles โ an unpatched machine is the attacker’s easiest target.
-
Enable Windows Defender and keep definitions current. Microsoft’s built-in security tooling adds behavioural detection layers that can catch exploitation attempts even before a dedicated patch exists.
-
Audit internet-facing Exchange servers. If you run on-premises Exchange, ensure it is current on Cumulative Updates (CUs) and Security Updates (SUs). Consider whether any exposure can be reduced while patches are in progress.
-
Apply the principle of least privilege. Privilege escalation exploits are far less damaging when user accounts already operate with minimal permissions.
-
Monitor for unusual behaviour. Lateral movement, unexpected process creation, and new scheduled tasks are common post-exploitation indicators โ security information and event management (SIEM) tools can flag these automatically.
-
Review your backup strategy. In a worst-case scenario, clean, tested, offline backups are your most reliable recovery mechanism.
Why Running a Genuine, Fully Licensed Windows 11 Matters for Security
One practical takeaway from events like Pwn2Own is that security patches are your first and most reliable line of defence โ and they only arrive on licensed, genuine copies of Windows. Pirated or improperly activated copies of Windows 11 are routinely blocked from receiving Windows Update patches, meaning users on counterfeit licences are unknowingly running permanently unpatched systems. Every Windows 11 security zero-day exploit demonstrated at Pwn2Own will eventually receive a patch; the question is whether your machine is eligible to receive it.
If you’re running Windows 11 on a legitimate key, you’re already in the best position to receive those patches the moment Microsoft ships them. If you’re unsure about your licence status, now is the time to sort it. ShopKeyOnline offers genuine Windows 11 Pro Retail keys with instant email delivery, ensuring your system stays within Microsoft’s update ecosystem โ and keeps receiving every critical security fix as it lands. For businesses deploying across multiple machines, the Windows 11 Pro OEM licence is a cost-effective way to ensure every endpoint is genuinely activated and patch-eligible.
The Bigger Picture: Enterprise Security in a Zero-Day World
Pwn2Own Berlin 2026 is a reminder that software vulnerabilities are an inevitable feature of complex systems, not a sign of vendor negligence. Every major platform โ Windows, Linux, macOS, Exchange, VMware โ has appeared on the Pwn2Own target list and fallen at some point. The goal is not to be surprised by zero-days but to build security postures that minimise the blast radius when they are eventually exploited.
For enterprise teams, this means layered defence: endpoint detection and response (EDR) tools, network segmentation, privileged access workstations (PAWs), and aggressive patch management. For individual users and small businesses, it means something simpler but equally important: keep Windows updated, run Windows Defender, and use genuine software that doesn’t lock you out of the security update pipeline.
The security community’s response to events like Pwn2Own is, ultimately, a healthy one. Responsible disclosure keeps the most dangerous techniques out of criminal hands while forcing vendors to fix what they might otherwise deprioritise. The system works โ but only if the patch reaches your machine.
FAQ: Windows 11 Zero-Day Exploits Explained
What is a zero-day exploit in Windows 11?
A zero-day exploit is an attack that targets a vulnerability in Windows 11 that the software vendor (Microsoft) has not yet patched. The term “zero-day” reflects the fact that the vendor has had zero days to prepare a fix. Until a patch is issued and applied, systems remain exposed to exploitation via that specific flaw.
Is my Windows 11 PC at risk after Pwn2Own 2026?
The direct risk to home and small-business users is low in the immediate aftermath of Pwn2Own, because exploit details are not published and are shared only with Microsoft under responsible disclosure. However, the risk is not zero โ nation-state actors and advanced criminal groups invest heavily in independent vulnerability research. Applying all pending Windows updates promptly is the single most effective mitigation.
How long does Microsoft take to patch a Pwn2Own zero-day?
Under ZDI’s standard disclosure policy, Microsoft has up to 90 days to issue a patch before vulnerability details are made public. In practice, Microsoft typically targets the next Patch Tuesday cycle after being notified. For Pwn2Own Berlin 2026 disclosures from mid-May, the June 2026 Patch Tuesday (10 June) and July 2026 Patch Tuesday are the most likely patch delivery dates.
Does Windows Defender protect against zero-day exploits?
Windows Defender’s real-time protection and behavioural analysis layers can detect and block many exploit techniques โ including some zero-day attack patterns โ even before a signature-based update is available. However, no single security tool provides complete protection against all zero-day scenarios. A layered approach combining patching, behavioural monitoring, and least-privilege access is recommended.
Why is Microsoft Exchange targeted so frequently at Pwn2Own?
Exchange is a high-value target because it handles sensitive email data, integrates deeply with Active Directory, and is often exposed to the internet. Successful exploitation can yield access to an organisation’s entire communications history and potentially pivot into broader network compromise. Its complex codebase โ built up over decades โ also provides a large attack surface for researchers to analyse.
Will upgrading to Windows 11 protect me from these vulnerabilities?
Windows 11 is Microsoft’s most actively maintained OS and receives security patches more rapidly than older versions like Windows 10, whose support ends in October 2026. Running a fully patched, genuine copy of Windows 11 puts you in the best possible position to receive fixes for vulnerabilities like those demonstrated at Pwn2Own. It does not make you invulnerable โ no OS can claim that โ but it ensures you benefit from every patch Microsoft ships.