Pwn2Own Berlin 2026 Day Two: Microsoft Exchange RCE-as-SYSTEM Chain and 14 Other Zero-Days Disclosed — Threadlinqs Intelligence
As of 2026-05-15, Pwn2Own Berlin 2026 Day Two: Microsoft Exchange RCE-as-SYSTEM Chain and 14 Other Zero-Days Disclosed is a high-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 33 indicators of compromise.
Threat ID: TL-2026-1547 · Severity: HIGH · Status: ACTIVE · Category: VULNERABILITY
At Pwn2Own Berlin 2026 Day Two (2026-05-15), Orange Tsai (DEVCORE) chained three previously-unknown, unpatched bugs to achieve remote code execution as SYSTEM against a fully-patched Microsoft
On May 15, 2026 (Day Two of the three-day Pwn2Own Berlin 2026 contest, co-located with OffensiveCon), Trend Micro's Zero Day Initiative (ZDI) hosted live demonstrations of 15 unique zero-day exploit chains, paying out $385,750. The headline entry came from Orange Tsai of DEVCORE, who chained three distinct, previously-unknown vulnerabilities to achieve remote code execution as SYSTEM against a fully-patched on-premises Microsoft Exchange Server instance, earning the contest's single highest reward of $200,000 and 20 Master of Pwn points. The chain grants an attacker who begins with only low-privileged access to reach full SYSTEM-level compromise of enterprise mail/collaboration infrastructure -- a capability class with direct precedent in Orange Tsai's prior real-world Exchange chains (ProxyLogon, ProxyShell, ProxyNotShell), which were weaponized at scale by ransomware affiliates and nation-state actors (HAFNIUM/APT) within days of prior ZDI/Pwn2Own-style disclosures. Orange Tsai also compromised Microsoft Edge via a four-logic-bug sandbox escape on Day One ($175,000) and contributed to DEVCORE's overall Master of Pwn win ($505,000, 50.5 points across the full event), which additionally included a Windows 11 privilege-escalation win via an Improper Access Control bug (Angelboy & TwinkleStar03, Day One, $30,000) and a Microsoft SharePoint compromise later in the event.
Beyond Exchange, Day Two produced a wide spread of successful zero-day demonstrations spanning both classic enterprise/OS targets and the emerging AI-toolchain attack surface: Cursor IDE was exploited twice (Le Duc Anh Vu/Viettel Cyber Security, $30,000; a Compass Security team, $15,000); Red Hat Enterprise Linux was compromised via a use-after-free privilege-escalation bug (Ben Koo/Team DDOS, $10,000); LM Studio fell to a code-injection bug (OtterSec, $20,000); NVIDIA Container Toolkit was compromised via a use-after-free bug (0xDACA & Noam Trobinski, $25,000); OpenAI Codex was exploited by Sina Kheirkhah ($20,000); and Windows 11 was hit again via an integer-overflow bug (Siyeon Wi, $7,500). Several additional entries were scored as 'collisions' with bugs already known to the vendor -- Sina Kheirkhah against Claude Desktop ($10,000), STARLabs SG against NVIDIA Megatron Bridge ($2,500), and Out Of Bounds teams against Ollama and LiteLLM (combined $45,750). Attempts against Palo Alto Networks (Safari), Rapid7 (SharePoint), Abstract Team (RHEL), and Viettel (Firefox) failed to complete within the allotted time on Day Two.
Across the full three-day event (May 14-16, 2026), researchers were paid $1,298,250 total for 47 unique zero-day vulnerabilities across Day One ($523,000/24 bugs), Day Two ($385,750/15 bugs), and Day Three ($389,500/8 bugs, including a VMware ESXi virtualization escape and a second SharePoint compromise). No CVE identifiers have been assigned to any of the disclosed bugs as of this writing. Per ZDI's standard responsible-disclosure process, all affected vendors (Microsoft, Red Hat, NVIDIA, VMware, Cursor/Anysphere, OpenAI, LM Studio, Ollama, LiteLLM, Anthropic) have a 90-day window from the contest date to ship patches before ZDI publishes full technical write-ups and proof-of-concept details. Historically, ZDI/Pwn2Own-originated Exchange and Windows privilege-escalation bugs have been reverse-engineered from patch diffs and weaponized by criminal and state-sponsored actors well inside that 90-day window once patches ship, making this disclosure a high-priority item for detection engineering and patch-readiness planning ahead of public technical disclosure (expected on or around 2026-08-13, 90 days after May 15, 2026).
Weaknesses (CWE)
CWE-416, CWE-190, CWE-284, CWE-150, CWE-94
Target sectors: technology, enterprise it, government administration, finance, health, software development, cloud ai infrastructure
Target regions: Global
References
- Pwn2Own Berlin 2026 – Day Two Results
- Zero Day Initiative — Pwn2Own Berlin 2026 - Day One Results
- Zero Day Initiative — Pwn2Own Berlin 2026: The Full Schedule
- Hackers earn $1,298,250 for 47 zero-days at Pwn2Own Berlin 2026
- Microsoft Exchange, Windows 11, and Cursor Zero-Days Exploited on Pwn2Own Day 2
- Microsoft Exchange zero-day chain nets DEVCORE $200K at Pwn2Own
- Pwn2Own Berlin 2026 Closes With $1.3 Million in Zero-Day Payouts
- Pwn2Own Berlin 2026: On the Ground with ZDI's Biggest AI Showdown Yet
- Pwn2Own Berlin 2026: Security Researchers Collect $523K on Day One with 24 Windows and Edge Zero-Days
- Pwn2Own Berlin 2026, Day One: $523,000 paid out, AI products fall
- Microsoft Edge, Windows 11 and LiteLLM Hacked in Pwn2Own Berlin 2026
- Pwn2Own Berlin 2026 Results: DEVCORE Wins Master of Pwn, $1.3M Paid for 47 Zero-Days
- Pwn2Own Berlin 2026, 47 Zero-Days and the New AI Toolchain Attack Surface
- Microsoft Exchange, Windows 11 hacked on second day of Pwn2Own
- International Cyber Digest — Orange Tsai $375,000 in 24 hours at Pwn2Own Berlin 2026
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 33 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, HIGH, threat intelligence, cybersecurity, T1190, T1203, T1505, T1068, T1548, T1211, T1610, T1003, T1082, T1210