Cyber & Technology — 2026-05-17

Pwn2Own Berlin 2026 Concludes with $1.3 Million Paid for 47 Zero-Day Vulnerabilities

BLUFDemonstrated exploitation of OpenAI Codex confirms AI-assisted development tools now carry the same exploitable attack surface as legacy enterprise software, a risk enterprise procurement has yet to price into vendor evaluations.

The Pwn2Own Berlin 2026 hacking competition concluded May 17 with DEVCORE crowned Master of Pwn after researchers demonstrated 47 unique zero-day vulnerabilities across enterprise systems, AI platforms, and developer tools, earning $1,298,250 total. Successful exploits targeted OpenAI Codex, VMware ESXi, Microsoft SharePoint, and Mozilla Firefox among other products. The event marked the first inclusion of AI platform targets in the Pwn2Own competition series.

Analysis
Berlin's 47 zero-days against Vancouver 2025's 32 signal that offensive research is outpacing defensive patching across both traditional enterprise software and AI infrastructure, a pattern the concurrent Calif M5 kernel exploit reinforces, per a single Cyber Insider report pending ZDI confirmation. Successful exploitation of OpenAI Codex establishes that AI-assisted development tools carry an attack surface enterprise procurement has not priced into risk models. The count may instead reflect incentive design: higher AI-target payouts redirected research effort that would otherwise have targeted traditional software, overstating any genuine acceleration in exploitable attack surface.
1 sources
  1. Pwn2Own Berlin 2026 concludes with $1.29 million paid for 47 zero-days - Cyber Insider

View in full brief →

UNCLASSIFIED // OPEN SOURCE