Pwn2Own Berlin 2026 Day Three: Zero-Days Demonstrated in VMware ESXi, Microsoft SharePoint, Windows 11, Red Hat Linux, and Anthropic Claude Code — Threadlinqs Intelligence
As of 2026-07-19, Pwn2Own Berlin 2026 Day Three: Zero-Days Demonstrated in VMware ESXi, Microsoft SharePoint, Windows 11, Red Hat Linux, and Anthropic Claude Code is a high-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 33 indicators of compromise.
Threat ID: TL-2026-1546 · Severity: HIGH · Status: ACTIVE · Category: VULNERABILITY
At Pwn2Own Berlin 2026 (OffensiveCon, May 14-16, 2026), competing research teams demonstrated 47 unique zero-day exploit chains for a record $1,298,250 payout, including a $200,000 VMware ESXi
Pwn2Own Berlin 2026, organized by Trend Micro's Zero Day Initiative (ZDI) and co-located with OffensiveCon, ran May 14-16, 2026 and closed with 47 unique zero-day vulnerabilities disclosed for a total of $1,298,250 - a roughly 20% increase over the prior year's $1,078,750. ZDI reported a 450% year-over-year surge in contest submissions, which Dustin Childs (ZDI head of threat awareness) attributed to researchers using AI coding tools both to discover bugs and to draft the documentation required for contest registration; nearly 100 entries arrived in the final 72 hours before registration closed, forcing ZDI to reject over 150 working zero-day chains for the first time in the event's 19-year history and to deploy its own agentic-AI triage pipeline to filter submissions down to a reviewable volume.
Day One (24 unique 0-days, $523,000) featured Orange Tsai (DEVCORE) chaining four logic bugs to escape the Microsoft Edge sandbox ($175,000/17.5 pts), Valentina Palmiotti (IBM X-Force) rooting an NVIDIA Container Toolkit 0-day ($50,000) and Red Hat Linux for Workstations ($20,000), and k3vg3n chaining SSRF plus code injection to exploit LiteLLM ($40,000/4 pts). Day Two (15 unique 0-days, $385,750, running total $908,750) featured Cheng-Da Tsai/Orange Tsai (DEVCORE) chaining three bugs for unauthenticated remote code execution as SYSTEM against Microsoft Exchange ($200,000), Siyeon Wi escalating privileges on Windows 11 via integer overflow ($7,500/3 pts), and Ben Koo (Team DDOS) rooting Red Hat Enterprise Linux for Workstations ($10,000).
Day Three (final day, bringing the contest to $1,298,250 / 47 zero-days) delivered the highest single payout of the event: Nguyen Hoang Thach of STARLabs SG chained a memory-corruption bug in VMware ESXi with the contest's Cross-tenant Code Execution add-on objective for $200,000 and 20 Master of Pwn points - a hypervisor escape with direct cross-tenant blast radius in shared virtualization environments. splitline of DEVCORE Research Team chained two distinct bugs to achieve exploitation of Microsoft SharePoint for $100,000 and 10 points. Le Tran Hai Tung, dungnm, and hieuvd of Viettel Cyber Security used an integer overflow to escalate privileges on Windows 11 in the event's fifth successful round against that target, earning $7,500 and 3 points. Hyunwoo Kim chained a use-after-free with an uninitialized-memory read to escalate privileges on Red Hat Enterprise Linux for Workstations, earning $5,000 and 2 points. Sina Kheirkhah of Summoning Team scored a partial-credit collision against Red Hat Linux (one bug previously known) for $7,000 and 1.5 points, while a teammate, Giuseppe Cali, timed out attempting a separate VMware ESXi entry.
The contest's newly introduced 'Coding Agent' category - covering Anthropic Claude Code, OpenAI Codex, and Cursor - drew sustained attention across all three days as ZDI required exploits to originate from realistic coding-agent use cases and to cross a sandbox or permission boundary (i.e., achieve impact beyond the agent's intended blast radius, such as host code execution or unauthorized external control). Satoki Tsuji of Ikotas Labs abused an external control/permission-boundary flaw in OpenAI Codex to trigger unintended behavior and spawn multiple calculator instances (a canonical PoC-of-concept RCE demonstration), earning $20,000 and 4 points - the third successful Codex compromise of the event. Anthropic Claude Code was hit twice on Day Three, both as partial-credit collisions rather than fresh zero-days: a five-person Compass Security team (Emanuele Barbeno, Cyrill Bannwart, Yves Bieri, Lukasz D., Urs Mueller) triggered a one-vulnerability collision with a bug from an earlier attempt, and Byung Young Yi of Out Of Bounds independently reproduced a previously disclosed Claude Code bug; each collision still paid $20,000 and 2 Master of Pwn points under ZDI's partial-credit rules. Analysis from Trend Micro and independent researchers characterized the AI coding-a
Weaknesses (CWE)
CWE-416, CWE-457, CWE-190, CWE-787, CWE-269, CWE-284
Target sectors: technology, cloud hosting, government administration, finance, health, critical-infrastructure, software-development
Target regions: Global, North America, Europe, Asia
References
- Pwn2Own Berlin 2026 - Day Three Results and Master of Pwn
- Pwn2Own Berlin 2026, Day Three: DEVCORE Crowned Master of Pwn, $1.298 Million Total
- Pwn2Own Berlin 2026 concludes with $1.29 million paid for 47 zero-days
- Pwn2Own Berlin 2026, 47 Zero-Days and the New AI Toolchain Attack Surface
- Pwn2Own Berlin 2026: AI Broke the Contest Built to Test It
- Pwn2Own Berlin 2026 Results: DEVCORE Wins Master of Pwn, $1.3M Paid for 47 Zero-Days
- GenAI Is Both Hunter and Hunted at Pwn2Own Berlin 2026
- Zero Day Initiative - Pwn2Own Berlin 2026 - Day Two Results
- Pwn2Own Berlin 2026, Day Two: $385,750 more, Microsoft Exchange falls, and the running total crosses $900K
- Pwn2Own Berlin 2026, Day One: $523,000 paid out, AI products fall
- Hackers earn $1,298,250 for 47 zero-days at Pwn2Own Berlin 2026
- Captured Logs Reveal Hackers Using Claude and Codex to Breach Companies
- Pwn2Own Berlin 2026: On the Ground with ZDI's Biggest AI Showdown Yet
- Pwn2Own Berlin 2026 day two: Exchange, Windows 11, and AI tooling fall to fresh zero-days
- Pwn2Own Berlin 2026 Closes With $1.3 Million in Zero-Day Payouts
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 33 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, HIGH, threat intelligence, cybersecurity, T1190, T1199, T1195, T1203, T1059, T1204, T1068, T1611, T1548, T1211