• News/
  • bleepingcomputer-20260515174725

Microsoft Exchange, Windows 11 hacked on second day of Pwn2Own

BleepingComputer
·
Sergiu Gatlan
·
Published May 15, 2026
·
Updated

​During the second day of Pwn2Own Berlin 2026, competitors collected $385,750 in cash awards after exploiting 15 unique zero-day vulnerabilities in multiple products, including Windows 11, Microsoft Exchange, and Red Hat Enterprise Linux for Workstations. The Pwn2Own Berlin 2026 hacking competition takes place at the OffensiveCon conference from May 14 to May 16 and focuses on enterprise technologies and artificial intelligence. Security researchers can earn over $1,000,000 in cash and prizes by hacking fully patched products in the web browser, enterprise applications, cloud-native/container environments, virtualization, local privilege escalation, servers, local inference, and LLM categories. According to Pwn2Own's rules, all targeted devices run the latest operating system versions, and all entries must compromise the target and demonstrate arbitrary code execution. Vendors have 90 days to patch their software and hardware after the zero-days are disclosed at Pwn2Own. The highlight of the second day was Cheng-Da Tsai (also known as Orange Tsai) of DEVCORE Research Team earning $200,000 after chaining three bugs to gain remote code execution with SYSTEM privileges on Microsoft Exchange. Siyeon Wi also collected $7,500 after exploiting an integer overflow bug to hack Windows 11, and Ben Koo of Team DDOS escalated privileges to root on Red Hat Enterprise Linux for Workstations to earn a $10,000 cash prize, while 0xDACA and Noam Trobishi used a use-after-free bug to exploit t...

Read full article

Affected Software

10 affected components
Microsoft Exchange
Microsoft Windows 11
Red Hat Enterprise Linux for Workstations
Red Hat Linux for Workstations
Nvidia Container Toolkit
Cursor AI coding agent
OpenAI Codex
Microsoft Edge
VMware ESXi
Microsoft SharePoint
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What event is discussed in the article?

The article discusses the second day of the Pwn2Own Berlin 2026 hacking competition.

2

What products were targeted during the hacking competition?

The products targeted included Windows 11, Microsoft Exchange, and Red Hat Enterprise Linux.

3

How much in cash awards was distributed during the event?

Competitors collected a total of $385,750 in cash awards for exploiting vulnerabilities.

4

What types of vulnerabilities were exploited?

The competitors exploited 15 unique zero-day vulnerabilities across multiple software products.

5

What implications does this event have for software security?

The event highlights the ongoing risks and vulnerabilities present in widely used software solutions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203