Pwn2Own Berlin 2026: participants earned a total of $1,298,250 for 47 vulnerabilities, with successful exploits of AI products like Codex, Cursor, and LM Studio
Participants demonstrated exploits for Windows, Linux, VMware, Nvidia, and AI products. … Pwn2Own Berlin 2026 has come to an end …
Context & Ripple Effects
Pwn2Own’s recent coverage has repeatedly shown fully patched mainstream products yielding large numbers of zero-days, from Windows, Ubuntu and Tesla in Vancouver to consumer devices in Toronto. Berlin extends that familiar disclosure-and-patching cycle into AI developer products alongside operating systems, virtualization and Nvidia-related targets.
The event’s 47 vulnerabilities and roughly $1.3 million in awards make AI tooling a material part of a mature offensive-security testing venue rather than an isolated research exercise.
First-order effects
- The affected AI-product vendors, as well as Windows, Linux, VMware and Nvidia-related product teams, receive vulnerability disclosures that require triage, fixes and coordinated updates.
- Users of the demonstrated products face a near-term patch-management task as vendors turn the disclosed exploit paths into releases and advisories.
Second-order effects
- AI coding-tool providers will face stronger pressure to match the vulnerability-response discipline expected of established platform vendors, especially where their products operate on developers’ code or local environments.
- Enterprise buyers assessing AI tools may place greater weight on patch cadence, disclosure practices and deployability of security updates, not only model capability and workflow features.
Third-order effects
- If AI products continue appearing as recurring Pwn2Own targets, AI application security is likely to be treated increasingly as endpoint and software-supply-chain security, with independent exploit testing becoming a more visible product-quality signal.
- The pattern could shift competition toward vendors able to combine rapid AI-product iteration with dependable remediation processes; the corpus does not establish whether this will become a lasting benchmark across the sector.
The trend: AI developer products are moving into the same public vulnerability-disclosure and patch-accountability cycle long associated with major operating systems, devices and infrastructure platforms.