Pwn2Own Berlin 2026 Day Two: Microsoft Exchange RCE-as-SYSTEM Chain and 14 Other Zero-Days Disclosed

Pwn2Own Berlin 2026 Day Two (TL-2026-1547), also tracked as Pwn2Own Berlin 2026 Day Two, is a high-severity software vulnerability, first published 2026-05-15. It has no confirmed attribution, affects Microsoft Exchange Server, maps to 15 MITRE ATT&CK techniques (T1003, T1068, T1071), and is covered by 9 detection rules and 33 indicators of compromise.

Key facts for TL-2026-1547

Threat ID
TL-2026-1547
Also known as
Pwn2Own Berlin 2026 Day Two, DEVCORE Exchange RCE-as-SYSTEM Chain
Severity
HIGH
Status
ACTIVE
Category
VULNERABILITY
First published
2026-05-15
Last reviewed
2026-05-15
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
technology, enterprise it, government administration, finance, health, software development, cloud ai infrastructure
Target regions
Global
Detection rules
9
Indicators of compromise
33

At Pwn2Own Berlin 2026 Day Two (2026-05-15), Orange Tsai (DEVCORE) chained three previously-unknown, unpatched bugs to achieve remote code execution as SYSTEM against a fully-patched Microsoft Exchange server, earning $200,000. Fourteen additional zero-days were demonstrated the same day against Cursor, OpenAI Codex, LM Studio, NVIDIA Container Toolkit, Red Hat Enterprise Linux, Microsoft Windows 11, LiteLLM, Ollama, and NVIDIA Megatron Bridge.

How Pwn2Own Berlin 2026 Day Two works

On May 15, 2026 (Day Two of the three-day Pwn2Own Berlin 2026 contest, co-located with OffensiveCon), Trend Micro's Zero Day Initiative (ZDI) hosted live demonstrations of 15 unique zero-day exploit chains, paying out $385,750. The headline entry came from Orange Tsai of DEVCORE, who chained three distinct, previously-unknown vulnerabilities to achieve remote code execution as SYSTEM against a fully-patched on-premises Microsoft Exchange Server instance, earning the contest's single highest reward of $200,000 and 20 Master of Pwn points. The chain grants an attacker who begins with only low-privileged access to reach full SYSTEM-level compromise of enterprise mail/collaboration infrastructure -- a capability class with direct precedent in Orange Tsai's prior real-world Exchange chains (ProxyLogon, ProxyShell, ProxyNotShell), which were weaponized at scale by ransomware affiliates and nation-state actors (HAFNIUM/APT) within days of prior ZDI/Pwn2Own-style disclosures. Orange Tsai also compromised Microsoft Edge via a four-logic-bug sandbox escape on Day One ($175,000) and contributed to DEVCORE's overall Master of Pwn win ($505,000, 50.5 points across the full event), which additionally included a Windows 11 privilege-escalation win via an Improper Access Control bug (Angelboy & TwinkleStar03, Day One, $30,000) and a Microsoft SharePoint compromise later in the event.

Beyond Exchange, Day Two produced a wide spread of successful zero-day demonstrations spanning both classic enterprise/OS targets and the emerging AI-toolchain attack surface: Cursor IDE was exploited twice (Le Duc Anh Vu/Viettel Cyber Security, $30,000; a Compass Security team, $15,000); Red Hat Enterprise Linux was compromised via a use-after-free privilege-escalation bug (Ben Koo/Team DDOS, $10,000); LM Studio fell to a code-injection bug (OtterSec, $20,000); NVIDIA Container Toolkit was compromised via a use-after-free bug (0xDACA & Noam Trobinski, $25,000); OpenAI Codex was exploited by Sina Kheirkhah ($20,000); and Windows 11 was hit again via an integer-overflow bug (Siyeon Wi, $7,500). Several additional entries were scored as 'collisions' with bugs already known to the vendor -- Sina Kheirkhah against Claude Desktop ($10,000), STARLabs SG against NVIDIA Megatron Bridge ($2,500), and Out Of Bounds teams against Ollama and LiteLLM (combined $45,750). Attempts against Palo Alto Networks (Safari), Rapid7 (SharePoint), Abstract Team (RHEL), and Viettel (Firefox) failed to complete within the allotted time on Day Two.

Across the full three-day event (May 14-16, 2026), researchers were paid $1,298,250 total for 47 unique zero-day vulnerabilities across Day One ($523,000/24 bugs), Day Two ($385,750/15 bugs), and Day Three ($389,500/8 bugs, including a VMware ESXi virtualization escape and a second SharePoint compromise). No CVE identifiers have been assigned to any of the disclosed bugs as of this writing. Per ZDI's standard responsible-disclosure process, all affected vendors (Microsoft, Red Hat, NVIDIA, VMware, Cursor/Anysphere, OpenAI, LM Studio, Ollama, LiteLLM, Anthropic) have a 90-day window from the contest date to ship patches before ZDI publishes full technical write-ups and proof-of-concept details. Historically, ZDI/Pwn2Own-originated Exchange and Windows privilege-escalation bugs have been reverse-engineered from patch diffs and weaponized by criminal and state-sponsored actors well inside that 90-day window once patches ship, making this disclosure a high-priority item for detection engineering and patch-readiness planning ahead of public technical disclosure (expected on or around 2026-08-13, 90 days after May 15, 2026).

MITRE ATT&CK techniques used in TL-2026-1547

Credential Access

T1003 OS Credential Dumping

Privilege Escalation

T1068 Exploitation for Privilege Escalation; T1548 Abuse Elevation Control Mechanism

Command and Control

T1071 Application Layer Protocol

Discovery

T1082 System Information Discovery

Collection

T1114 Email Collection

Initial Access

T1190 Exploit Public-Facing Application

Execution

T1203 Exploitation for Client Execution

Lateral Movement

T1210 Exploitation of Remote Services

Defense Evasion

T1211 Exploitation for Stealth

Impact

T1489 Service Stop

Persistence

T1505 Server Software Component

Resource Development

T1585 Establish Accounts

Reconnaissance

T1595 Active Scanning

execution

T1610 Deploy Container

Affected products and versions in Pwn2Own Berlin 2026 Day Two

  • Microsoft — Exchange Server
    Vulnerable versions: fully-patched on-premises build as of 2026-05-15
    Fixed in: none released as of 2026-05-15 (90-day disclosure window)
  • Microsoft — Windows 11
    Vulnerable versions: fully-patched build as of 2026-05-13/2026-05-15
    Fixed in: none released as of 2026-05-15
  • Microsoft — SharePoint
    Vulnerable versions: fully-patched on-premises build as of Pwn2Own Berlin 2026
    Fixed in: none released as of 2026-05-16
  • Microsoft — Edge
    Vulnerable versions: fully-patched build as of 2026-05-14
    Fixed in: none released as of 2026-05-15
  • Red Hat — Enterprise Linux
    Vulnerable versions: current GA build as of 2026-05-15
    Fixed in: none released as of 2026-05-15
  • NVIDIA — Container Toolkit
    Vulnerable versions: current release as of 2026-05-15
    Fixed in: none released as of 2026-05-15
  • NVIDIA — Megatron Bridge
    Vulnerable versions: current release as of 2026-05-15
    Fixed in: none released as of 2026-05-15
  • Anysphere — Cursor
    Vulnerable versions: current release as of 2026-05-15
    Fixed in: none released as of 2026-05-15
  • OpenAI — Codex
    Vulnerable versions: current release as of 2026-05-14/2026-05-15
    Fixed in: none released as of 2026-05-15
  • Element Labs — LM Studio
    Vulnerable versions: current release as of 2026-05-15
    Fixed in: none released as of 2026-05-15

Remediation for Pwn2Own Berlin 2026 Day Two

Patches

  • No vendor patches exist yet -- all 47 bugs disclosed at Pwn2Own Berlin 2026 (including the Exchange RCE-as-SYSTEM chain) are within the standard 90-day ZDI vendor disclosure window as of 2026-05-15; monitor Microsoft, Red Hat, NVIDIA, VMware, Anysphere (Cursor), OpenAI, LM Studio, Ollama, LiteLLM, and Anthropic advisories for forthcoming fixes

Immediate actions

  • Track ZDI advisories for the affected products (Microsoft Exchange, Windows 11, Red Hat Enterprise Linux, NVIDIA Container Toolkit, Cursor, OpenAI Codex, LM Studio, Ollama, LiteLLM, NVIDIA Megatron Bridge, Claude Desktop, Microsoft SharePoint, Microsoft Edge, VMware ESXi) and pre-stage patch deployment for the 90-day disclosure window ending on or around 2026-08-13
  • Restrict and monitor low-privileged/initial-foothold access paths to on-premises Exchange servers, since the demonstrated chain begins from low privilege and escalates to SYSTEM
  • Ensure Exchange, SharePoint, and Windows Server EDR/telemetry is tuned for anomalous w3wp.exe / IIS worker-process child-process spawning and unexpected SYSTEM-level process creation from mail/web application pools, consistent with prior ProxyLogon/ProxyShell-style post-exploitation
  • Review exposure of AI developer-tooling endpoints (Cursor, OpenAI Codex, LM Studio, Ollama, LiteLLM) that accept untrusted input or are network-reachable, given multiple zero-days across this category at the same event
  • Increase patch-cadence readiness for NVIDIA Container Toolkit and Red Hat Enterprise Linux hosts running containerized/GPU workloads given the demonstrated use-after-free privilege-escalation bugs

Workarounds

  • No official workarounds have been published since technical exploit details remain embargoed; apply general Exchange/Windows/RHEL hardening (least privilege, network segmentation, disabling unused services) as compensating controls until patches ship

Longer-term hardening

  • Deploy behavioral EDR with memory-safety-aware detection (use-after-free, integer-overflow exploitation patterns) on Windows Server, RHEL, and containerized GPU infrastructure
  • Adopt a defense-in-depth architecture for on-premises Exchange (network segmentation, least-privilege service accounts, disabling of legacy protocols) to blunt the impact of any single RCE-as-SYSTEM chain once public technical details are released
  • Build a vendor-patch-tracking process specifically for ZDI/Pwn2Own disclosures, given the historical pattern of rapid weaponization following prior Exchange-focused Pwn2Own chains (ProxyLogon, ProxyShell, ProxyNotShell)
  • Extend AI-toolchain governance to treat coding agents, local-inference runtimes, and LLM gateways (Cursor, Codex, LM Studio, Ollama, LiteLLM) as first-class attack surface requiring patch management and network isolation equivalent to traditional server software

Weaknesses (CWE) in Pwn2Own Berlin 2026 Day Two

CWE-416, CWE-190, CWE-284, CWE-150, CWE-94

Timeline of Pwn2Own Berlin 2026 Day Two

  • ZDI publishes the full Pwn2Own Berlin 2026 contest schedule, listing target categories including AI Databases, Coding Agents, Local Inference, NVIDIA products, web browsers, servers, OS security, and virtualization.
  • Pwn2Own Berlin 2026 Day One concludes with $523,000 paid for 24 unique zero-days, including Orange Tsai's four-logic-bug Microsoft Edge sandbox escape ($175,000) and Angelboy & TwinkleStar03's Windows 11 privilege escalation via Improper Access Control ($30,000).
  • The 90-day standard ZDI vendor disclosure window begins for all Day Two zero-days, including the Microsoft Exchange RCE-as-SYSTEM chain; no CVE identifiers have been assigned as of the contest date.
  • Exploitation attempts against Apple Safari (Palo Alto Networks), Microsoft SharePoint (Rapid7), Red Hat Enterprise Linux (Abstract Team), and Mozilla Firefox (Viettel) fail to complete within the allotted time on Day Two.
  • Fourteen additional zero-day exploit chains are successfully demonstrated on Day Two against Cursor (x2), OpenAI Codex, LM Studio, NVIDIA Container Toolkit, Red Hat Enterprise Linux, and Windows 11, plus collision entries against Claude Desktop, NVIDIA Megatron Bridge, Ollama, and LiteLLM; Day Two totals $385,750 across 15 unique bugs.
  • Orange Tsai (DEVCORE) chains three previously-unknown bugs to achieve remote code execution as SYSTEM against a fully-patched Microsoft Exchange server on Pwn2Own Berlin 2026 Day Two, earning $200,000 and 20 Master of Pwn points -- the contest's single highest payout.
  • Pwn2Own Berlin 2026 Day Three concludes the contest with $389,500 paid for 8 additional zero-days, including a VMware ESXi virtualization escape and a second Microsoft SharePoint compromise.
  • ZDI and multiple outlets publish the full event wrap-up: $1,298,250 total paid across three days for 47 unique zero-day vulnerabilities; DEVCORE Research Team wins Master of Pwn with 50.5 points and $505,000 in total rewards.
  • Estimated end of the 90-day vendor disclosure window for Day Two bugs (2026-05-15 + 90 days); absent vendor patches, ZDI is expected to publish full technical details and PoC-level write-ups for the Exchange chain and other unpatched Day Two zero-days around this date.

Sources cited for Pwn2Own Berlin 2026 Day Two

Threats related to Pwn2Own Berlin 2026 Day Two

Detection coverage for TL-2026-1547

As of 2026-05-15, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1547 across Splunk SPL, Microsoft KQL and Sigma, covering 33 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats