Pwn2Own Berlin 2026 Day Two: Microsoft Exchange RCE-as-SYSTEM Chain and 14 Other Zero-Days Disclosed
Pwn2Own Berlin 2026 Day Two (TL-2026-1547), also tracked as Pwn2Own Berlin 2026 Day Two, is a high-severity software vulnerability, first published 2026-05-15. It has no confirmed attribution, affects Microsoft Exchange Server, maps to 15 MITRE ATT&CK techniques (T1003, T1068, T1071), and is covered by 9 detection rules and 33 indicators of compromise.
Key facts for TL-2026-1547
- Threat ID
- TL-2026-1547
- Also known as
- Pwn2Own Berlin 2026 Day Two, DEVCORE Exchange RCE-as-SYSTEM Chain
- Severity
- HIGH
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- 2026-05-15
- Last reviewed
- 2026-05-15
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- technology, enterprise it, government administration, finance, health, software development, cloud ai infrastructure
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 33
At Pwn2Own Berlin 2026 Day Two (2026-05-15), Orange Tsai (DEVCORE) chained three previously-unknown, unpatched bugs to achieve remote code execution as SYSTEM against a fully-patched Microsoft Exchange server, earning $200,000. Fourteen additional zero-days were demonstrated the same day against Cursor, OpenAI Codex, LM Studio, NVIDIA Container Toolkit, Red Hat Enterprise Linux, Microsoft Windows 11, LiteLLM, Ollama, and NVIDIA Megatron Bridge.
How Pwn2Own Berlin 2026 Day Two works
On May 15, 2026 (Day Two of the three-day Pwn2Own Berlin 2026 contest, co-located with OffensiveCon), Trend Micro's Zero Day Initiative (ZDI) hosted live demonstrations of 15 unique zero-day exploit chains, paying out $385,750. The headline entry came from Orange Tsai of DEVCORE, who chained three distinct, previously-unknown vulnerabilities to achieve remote code execution as SYSTEM against a fully-patched on-premises Microsoft Exchange Server instance, earning the contest's single highest reward of $200,000 and 20 Master of Pwn points. The chain grants an attacker who begins with only low-privileged access to reach full SYSTEM-level compromise of enterprise mail/collaboration infrastructure -- a capability class with direct precedent in Orange Tsai's prior real-world Exchange chains (ProxyLogon, ProxyShell, ProxyNotShell), which were weaponized at scale by ransomware affiliates and nation-state actors (HAFNIUM/APT) within days of prior ZDI/Pwn2Own-style disclosures. Orange Tsai also compromised Microsoft Edge via a four-logic-bug sandbox escape on Day One ($175,000) and contributed to DEVCORE's overall Master of Pwn win ($505,000, 50.5 points across the full event), which additionally included a Windows 11 privilege-escalation win via an Improper Access Control bug (Angelboy & TwinkleStar03, Day One, $30,000) and a Microsoft SharePoint compromise later in the event.
Beyond Exchange, Day Two produced a wide spread of successful zero-day demonstrations spanning both classic enterprise/OS targets and the emerging AI-toolchain attack surface: Cursor IDE was exploited twice (Le Duc Anh Vu/Viettel Cyber Security, $30,000; a Compass Security team, $15,000); Red Hat Enterprise Linux was compromised via a use-after-free privilege-escalation bug (Ben Koo/Team DDOS, $10,000); LM Studio fell to a code-injection bug (OtterSec, $20,000); NVIDIA Container Toolkit was compromised via a use-after-free bug (0xDACA & Noam Trobinski, $25,000); OpenAI Codex was exploited by Sina Kheirkhah ($20,000); and Windows 11 was hit again via an integer-overflow bug (Siyeon Wi, $7,500). Several additional entries were scored as 'collisions' with bugs already known to the vendor -- Sina Kheirkhah against Claude Desktop ($10,000), STARLabs SG against NVIDIA Megatron Bridge ($2,500), and Out Of Bounds teams against Ollama and LiteLLM (combined $45,750). Attempts against Palo Alto Networks (Safari), Rapid7 (SharePoint), Abstract Team (RHEL), and Viettel (Firefox) failed to complete within the allotted time on Day Two.
Across the full three-day event (May 14-16, 2026), researchers were paid $1,298,250 total for 47 unique zero-day vulnerabilities across Day One ($523,000/24 bugs), Day Two ($385,750/15 bugs), and Day Three ($389,500/8 bugs, including a VMware ESXi virtualization escape and a second SharePoint compromise). No CVE identifiers have been assigned to any of the disclosed bugs as of this writing. Per ZDI's standard responsible-disclosure process, all affected vendors (Microsoft, Red Hat, NVIDIA, VMware, Cursor/Anysphere, OpenAI, LM Studio, Ollama, LiteLLM, Anthropic) have a 90-day window from the contest date to ship patches before ZDI publishes full technical write-ups and proof-of-concept details. Historically, ZDI/Pwn2Own-originated Exchange and Windows privilege-escalation bugs have been reverse-engineered from patch diffs and weaponized by criminal and state-sponsored actors well inside that 90-day window once patches ship, making this disclosure a high-priority item for detection engineering and patch-readiness planning ahead of public technical disclosure (expected on or around 2026-08-13, 90 days after May 15, 2026).
MITRE ATT&CK techniques used in TL-2026-1547
Credential Access
Privilege Escalation
T1068 Exploitation for Privilege Escalation; T1548 Abuse Elevation Control Mechanism
Command and Control
T1071 Application Layer Protocol
Discovery
T1082 System Information Discovery
Collection
Initial Access
T1190 Exploit Public-Facing Application
Execution
T1203 Exploitation for Client Execution
Lateral Movement
T1210 Exploitation of Remote Services
Defense Evasion
T1211 Exploitation for Stealth
Impact
Persistence
T1505 Server Software Component
Resource Development
Reconnaissance
execution
Affected products and versions in Pwn2Own Berlin 2026 Day Two
- Microsoft — Exchange Server
Vulnerable versions: fully-patched on-premises build as of 2026-05-15
Fixed in: none released as of 2026-05-15 (90-day disclosure window) - Microsoft — Windows 11
Vulnerable versions: fully-patched build as of 2026-05-13/2026-05-15
Fixed in: none released as of 2026-05-15 - Microsoft — SharePoint
Vulnerable versions: fully-patched on-premises build as of Pwn2Own Berlin 2026
Fixed in: none released as of 2026-05-16 - Microsoft — Edge
Vulnerable versions: fully-patched build as of 2026-05-14
Fixed in: none released as of 2026-05-15 - Red Hat — Enterprise Linux
Vulnerable versions: current GA build as of 2026-05-15
Fixed in: none released as of 2026-05-15 - NVIDIA — Container Toolkit
Vulnerable versions: current release as of 2026-05-15
Fixed in: none released as of 2026-05-15 - NVIDIA — Megatron Bridge
Vulnerable versions: current release as of 2026-05-15
Fixed in: none released as of 2026-05-15 - Anysphere — Cursor
Vulnerable versions: current release as of 2026-05-15
Fixed in: none released as of 2026-05-15 - OpenAI — Codex
Vulnerable versions: current release as of 2026-05-14/2026-05-15
Fixed in: none released as of 2026-05-15 - Element Labs — LM Studio
Vulnerable versions: current release as of 2026-05-15
Fixed in: none released as of 2026-05-15
Remediation for Pwn2Own Berlin 2026 Day Two
Patches
- No vendor patches exist yet -- all 47 bugs disclosed at Pwn2Own Berlin 2026 (including the Exchange RCE-as-SYSTEM chain) are within the standard 90-day ZDI vendor disclosure window as of 2026-05-15; monitor Microsoft, Red Hat, NVIDIA, VMware, Anysphere (Cursor), OpenAI, LM Studio, Ollama, LiteLLM, and Anthropic advisories for forthcoming fixes
Immediate actions
- Track ZDI advisories for the affected products (Microsoft Exchange, Windows 11, Red Hat Enterprise Linux, NVIDIA Container Toolkit, Cursor, OpenAI Codex, LM Studio, Ollama, LiteLLM, NVIDIA Megatron Bridge, Claude Desktop, Microsoft SharePoint, Microsoft Edge, VMware ESXi) and pre-stage patch deployment for the 90-day disclosure window ending on or around 2026-08-13
- Restrict and monitor low-privileged/initial-foothold access paths to on-premises Exchange servers, since the demonstrated chain begins from low privilege and escalates to SYSTEM
- Ensure Exchange, SharePoint, and Windows Server EDR/telemetry is tuned for anomalous w3wp.exe / IIS worker-process child-process spawning and unexpected SYSTEM-level process creation from mail/web application pools, consistent with prior ProxyLogon/ProxyShell-style post-exploitation
- Review exposure of AI developer-tooling endpoints (Cursor, OpenAI Codex, LM Studio, Ollama, LiteLLM) that accept untrusted input or are network-reachable, given multiple zero-days across this category at the same event
- Increase patch-cadence readiness for NVIDIA Container Toolkit and Red Hat Enterprise Linux hosts running containerized/GPU workloads given the demonstrated use-after-free privilege-escalation bugs
Workarounds
- No official workarounds have been published since technical exploit details remain embargoed; apply general Exchange/Windows/RHEL hardening (least privilege, network segmentation, disabling unused services) as compensating controls until patches ship
Longer-term hardening
- Deploy behavioral EDR with memory-safety-aware detection (use-after-free, integer-overflow exploitation patterns) on Windows Server, RHEL, and containerized GPU infrastructure
- Adopt a defense-in-depth architecture for on-premises Exchange (network segmentation, least-privilege service accounts, disabling of legacy protocols) to blunt the impact of any single RCE-as-SYSTEM chain once public technical details are released
- Build a vendor-patch-tracking process specifically for ZDI/Pwn2Own disclosures, given the historical pattern of rapid weaponization following prior Exchange-focused Pwn2Own chains (ProxyLogon, ProxyShell, ProxyNotShell)
- Extend AI-toolchain governance to treat coding agents, local-inference runtimes, and LLM gateways (Cursor, Codex, LM Studio, Ollama, LiteLLM) as first-class attack surface requiring patch management and network isolation equivalent to traditional server software
Weaknesses (CWE) in Pwn2Own Berlin 2026 Day Two
CWE-416, CWE-190, CWE-284, CWE-150, CWE-94
Timeline of Pwn2Own Berlin 2026 Day Two
- ZDI publishes the full Pwn2Own Berlin 2026 contest schedule, listing target categories including AI Databases, Coding Agents, Local Inference, NVIDIA products, web browsers, servers, OS security, and virtualization.
- Pwn2Own Berlin 2026 Day One concludes with $523,000 paid for 24 unique zero-days, including Orange Tsai's four-logic-bug Microsoft Edge sandbox escape ($175,000) and Angelboy & TwinkleStar03's Windows 11 privilege escalation via Improper Access Control ($30,000).
- The 90-day standard ZDI vendor disclosure window begins for all Day Two zero-days, including the Microsoft Exchange RCE-as-SYSTEM chain; no CVE identifiers have been assigned as of the contest date.
- Exploitation attempts against Apple Safari (Palo Alto Networks), Microsoft SharePoint (Rapid7), Red Hat Enterprise Linux (Abstract Team), and Mozilla Firefox (Viettel) fail to complete within the allotted time on Day Two.
- Fourteen additional zero-day exploit chains are successfully demonstrated on Day Two against Cursor (x2), OpenAI Codex, LM Studio, NVIDIA Container Toolkit, Red Hat Enterprise Linux, and Windows 11, plus collision entries against Claude Desktop, NVIDIA Megatron Bridge, Ollama, and LiteLLM; Day Two totals $385,750 across 15 unique bugs.
- Orange Tsai (DEVCORE) chains three previously-unknown bugs to achieve remote code execution as SYSTEM against a fully-patched Microsoft Exchange server on Pwn2Own Berlin 2026 Day Two, earning $200,000 and 20 Master of Pwn points -- the contest's single highest payout.
- Pwn2Own Berlin 2026 Day Three concludes the contest with $389,500 paid for 8 additional zero-days, including a VMware ESXi virtualization escape and a second Microsoft SharePoint compromise.
- ZDI and multiple outlets publish the full event wrap-up: $1,298,250 total paid across three days for 47 unique zero-day vulnerabilities; DEVCORE Research Team wins Master of Pwn with 50.5 points and $505,000 in total rewards.
- Estimated end of the 90-day vendor disclosure window for Day Two bugs (2026-05-15 + 90 days); absent vendor patches, ZDI is expected to publish full technical details and PoC-level write-ups for the Exchange chain and other unpatched Day Two zero-days around this date.
Sources cited for Pwn2Own Berlin 2026 Day Two
- Pwn2Own Berlin 2026 – Day Two Results
- Zero Day Initiative — Pwn2Own Berlin 2026 - Day One Results
- Zero Day Initiative — Pwn2Own Berlin 2026: The Full Schedule
- Hackers earn $1,298,250 for 47 zero-days at Pwn2Own Berlin 2026
- Microsoft Exchange, Windows 11, and Cursor Zero-Days Exploited on Pwn2Own Day 2
- Microsoft Exchange zero-day chain nets DEVCORE $200K at Pwn2Own
- Pwn2Own Berlin 2026 Closes With $1.3 Million in Zero-Day Payouts
- Pwn2Own Berlin 2026: On the Ground with ZDI's Biggest AI Showdown Yet
- Pwn2Own Berlin 2026: Security Researchers Collect $523K on Day One with 24 Windows and Edge Zero-Days
- Pwn2Own Berlin 2026, Day One: $523,000 paid out, AI products fall
- Microsoft Edge, Windows 11 and LiteLLM Hacked in Pwn2Own Berlin 2026
- Pwn2Own Berlin 2026 Results: DEVCORE Wins Master of Pwn, $1.3M Paid for 47 Zero-Days
- Pwn2Own Berlin 2026, 47 Zero-Days and the New AI Toolchain Attack Surface
- Microsoft Exchange, Windows 11 hacked on second day of Pwn2Own
- International Cyber Digest — Orange Tsai $375,000 in 24 hours at Pwn2Own Berlin 2026
Threats related to Pwn2Own Berlin 2026 Day Two
- Pwn2Own Berlin 2026 Day Three: Zero-Days Demonstrated in VMware ESXi, Microsoft SharePoint, Windows 11, Red Hat Linux, and Anthropic Claude Code
- CVE-2026-20230: Active Exploitation of Cisco Unified CM WebDialer SSRF Flaw Leading to Root-Level Compromise
- Fastjson RCE (≤ 1.2.83) — Active Exploitation Detected (ThreatBook XVE-2026-39684)
- CVE-2026-45659: Microsoft SharePoint Deserialization RCE Added to CISA KEV Despite 'Exploitation Less Likely' Rating
- CVE-2026-20251: Splunk Secure Gateway jsonpickle Deserialization RCE with Public PoC
- Four Chained Exploit Paths in LiteLLM Proxy (Pre-Auth RCE to Master Key Exfiltration) — STAR Labs Pwn2Own Research
Detection coverage for TL-2026-1547
As of 2026-05-15, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1547 across Splunk SPL, Microsoft KQL and Sigma, covering 33 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.