On Pwn2Own Berlin 2026 day 2, competitors earned $385,750 after exploiting 15 unique zero-day vulnerabilities in Windows 11, Red Hat Enterprise Linux and more
During the second day of Pwn2Own Berlin 2026, competitors collected $385,750 in cash awards after exploiting 15 unique zero …
Context & Ripple Effects
The Berlin event’s second day sits within a Pwn2Own record of researchers demonstrating zero-days against fully patched mainstream platforms, including earlier Windows, Linux, browser, vehicle and consumer-device targets.
Follow-up coverage says the Berlin competition ultimately produced 47 vulnerabilities and included AI products such as Codex, Cursor and LM Studio, expanding the event’s target set beyond the operating systems highlighted on day two.
First-order effects
- Windows 11, Red Hat Enterprise Linux and the other affected product makers must validate the demonstrated flaws and prioritize fixes or mitigations for the 15 unique zero-days disclosed through the contest.
- The competitors receive immediate cash rewards, while the event converts previously undisclosed research into vendor-facing vulnerability reports.
Second-order effects
- The concentration of successful demonstrations against patched products increases pressure on platform vendors to shorten the path from vulnerability intake to remediation and customer guidance.
- Adding AI products to the broader Berlin results gives security teams and researchers another product category to test alongside established OS and endpoint targets.
Third-order effects
- If Pwn2Own-style results continue to span operating systems, consumer devices and AI tools, vulnerability-management programs will need to treat AI application layers as a recurring attack surface rather than a separate experimental category.
- The event reinforces a market in which public, incentive-backed disclosure is used to surface flaws in widely deployed products before they are available to less accountable actors.
The trend: Pwn2Own is evolving from a test of core client platforms into a broader security proving ground that increasingly includes AI products alongside operating systems and consumer technology.