On the first day of Pwn2Own Berlin 2026, security researchers collected $523,000 in cash awards after exploiting 24 unique zero-days. Today's highlight was the attempt of Cheng-Da Tsai (also known as Orange Tsai) of DEVCORE Research Team, who was awarded $175,000 in rewards after chaining 4 logic bugs to achieve a sandbox escape on Microsoft Edge. Windows 11 was also hacked three times by Angelboy and TwinkleStar03 (working with the DEVCORE Internship Program), Marcin Wiązowski, and Kentaro Kawane of GMO Cybersecurity, each earning $30,000 in cash rewards for demonstrating new privilege escalation zero-days. Valentina Palmiotti (chompie) of IBM X-Force Offensive Research (XOR) also collected $20,000 after rooting Red Hat Linux for Workstations and another $50,000 for a zero-day in the NVIDIA Container Toolkit. Other successful attempts include k3vg3n chaining 3 bugs to take down LiteLLM ($40,000), Satoki Tsuji and haehae exploiting NVIDIA Megatron Bridge zero-days ($20,000), Compass Security and maitai of Doyensec hacking OpenAI's Codex coding agent (each earning $40,000), haehae dropping a Chroma zero-day ($20,000), and STARLabs SG a LM Studio zero-day ($40,000). The DEVCORE Research Team is now leading the competition with $205,000, followed by Valentina Palmiotti with $70,000. The Pwn2Own Berlin 2026 hacking contest, which focuses on enterprise technologies and artificial intelligence, takes place at the OffensiveCon conference from May 14 to May 16. On the second day, ...
Windows 11 and Microsoft Edge hacked at Pwn2Own Berlin 2026
BleepingComputer
·Sergiu Gatlan
·Published May 14, 2026
·Updated
Affected Software
12 affected components
Microsoft Edge
Microsoft Windows
Red Hat Linux for Workstations
Nvidia Container Toolkit
Nvidia Megatron Bridge
OpenAI Codex
Microsoft SharePoint
Microsoft Exchange
Apple Safari
Red Hat Enterprise Linux for Workstations
Anthropic Claude Code
Mozilla Firefox
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the hacking event at Pwn2Own Berlin 2026 where security researchers exploited vulnerabilities in Windows 11 and Microsoft Edge.
2
What significant amount of cash was awarded at this event?
Security researchers collected a total of $523,000 in cash awards after exploiting 24 unique zero-days.
3
Who was one of the key researchers mentioned in the article?
Orange Tsai is highlighted as a key researcher who earned $175,000 by chaining four logic bugs.
4
What specific software products were affected by the exploits?
The affected software includes Microsoft Edge, Microsoft Windows 11, and various products from NVIDIA and Red Hat.
5
What is a zero-day vulnerability?
A zero-day vulnerability is a security flaw that is unknown to the vendor and can be exploited by attackers before a patch is developed.