Pwn2Own Berlin 2026: Critical Flaws Hacked in Microsoft Edge, Windows 11, LiteLLM
Key Takeaways Pwn2Own Berlin 2026’s opening day saw significant zero-day exploits across major software and emerging AI platforms. Researchers successfully breached Microsoft Edge, Windows 11,...
Key Takeaways
- Pwn2Own Berlin 2026’s opening day saw significant zero-day exploits across major software and emerging AI platforms.
- Researchers successfully breached Microsoft Edge, Windows 11, and LiteLLM, uncovering 24 unique vulnerabilities and earning over half a million dollars.
- The event underscores the increasing vulnerability of AI ecosystems and core enterprise technologies to sophisticated, multi-stage attacks.
- Multiple vendors, including Microsoft, OpenAI, and NVIDIA, are affected by these newly discovered critical flaws.
The Pwn2Own Berlin 2026 competition kicked off with a flurry of successful zero-day exploits, demonstrating critical vulnerabilities in widely used software and cutting-edge artificial intelligence platforms. On its inaugural day, security researchers achieved breakthroughs against Microsoft Edge, Windows 11, and LiteLLM, collectively identifying 24 distinct vulnerabilities and securing payouts totaling $523,000.
Table Of Content
These initial findings from the competition underscore a critical shift in the cybersecurity landscape: sophisticated, chained attacks are increasingly targeting both established enterprise technologies and the rapidly evolving AI ecosystem.
Edge Sandbox Escape
One of the most impactful demonstrations came from Orange Tsai of the DEVCORE Research Team, who successfully executed a complex sandbox escape against Microsoft Edge. This exploit was particularly notable for chaining together four separate logic vulnerabilities, transforming what might otherwise be minor flaws into a full system compromise. The advanced technique earned DEVCORE $175,000 and 17.5 Master of Pwn points, positioning them as early leaders in the competition. This attack serves as a stark reminder that even modern browser security mechanisms can be bypassed when multiple weaknesses are strategically combined.
Windows 11 Privilege Escalations
Microsoft Windows 11 also proved to be a significant target, experiencing several successful privilege escalation attacks throughout the day. Researchers demonstrated various attack vectors, including those leveraging heap-based buffer overflows and use-after-free vulnerabilities. Notably, Angelboy and TwinkleStar03, also from DEVCORE, exploited an improper access control flaw to achieve elevated privileges. These repeated compromises highlight that even mature operating systems like Windows 11 remain susceptible to memory corruption and access control issues.
LiteLLM Exploited
AI infrastructure faced intense scrutiny, with LiteLLM succumbing to a full-chain exploit orchestrated by researcher k3vg3n. This attack combined three distinct vulnerabilities, including Server-Side Request Forgery (SSRF) and code injection, ultimately leading to a complete system takeover. The exploit secured $40,000 for k3vg3n and critically illuminated how AI frameworks, particularly those interacting with external inputs and APIs, can introduce severe security gaps if not robustly hardened.
AI and Developer Tools Under Pressure
Beyond LiteLLM, other AI-focused targets also experienced successful compromises. Compass Security researchers leveraged a CWE-150 flaw to exploit OpenAI Codex. NVIDIA’s Megatron Bridge was breached multiple times due to overly permissive allow lists and path-traversal vulnerabilities. Concurrently, IBM X-Force researchers successfully exploited a single bug within the NV Container Toolkit. These discoveries collectively reinforce concerns about the security maturity of AI and developer tooling ecosystems, suggesting ongoing challenges in secure design and resilience against threats.
Not every attempt at Pwn2Own Berlin 2026 succeeded. Several researchers failed to exploit targets such as OpenAI Codex and Oracle Autonomous AI Database within the allocated time. Additionally, multiple “collision” cases were reported, where working exploits relied on previously known vulnerabilities. While these cases still garnered rewards, they underscore a persistent issue: organizations’ failure to promptly patch known security flaws.
According to the Zero Day Initiative, the results from Day One of Pwn2Own Berlin 2026 signal a significant shift in the threat landscape. Attackers are no longer exclusively focused on traditional software but are now actively targeting AI platforms, inference engines, and developer tools. With DEVCORE currently leading the competition and more high-value targets slated for the coming days, the event is poised to uncover even deeper vulnerabilities, serving as a critical warning to vendors and enterprises alike.
What You Should Do
- Prioritize immediate patching for all Microsoft Edge and Windows 11 systems as updates become available, particularly for privilege escalation and sandbox escape vulnerabilities.
- For organizations utilizing LiteLLM or similar AI frameworks, conduct thorough security audits, focusing on input validation, API security, and access control mechanisms to mitigate SSRF and code injection risks.
- Review and harden configurations for AI and developer tools like OpenAI Codex, NVIDIA Megatron Bridge, and NV Container Toolkit, paying close attention to allow lists, path traversal protections, and overall access control.
- Implement a robust vulnerability management program to ensure prompt application of patches for all known security flaws, even those identified as “collisions” in competitions like Pwn2Own.
- Adopt a defense-in-depth strategy, including network segmentation, endpoint detection and response (EDR), and continuous monitoring, to detect and respond to sophisticated, chained attacks.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.