Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical WordPress Plugin Bug Exposes 600,000 Sites to File Upload Attacks
August 18, 2026
Critical VMware ESXi Vulnerability Lets Attackers Gain Root and Persistent SSH Access
August 18, 2026
Critical GitLab GraphQL Vulnerability Lets Attackers Delete Projects
August 18, 2026
Home/CyberSecurity News/Pwn2Own Berlin 2026: Critical Flaws Hacked in Microsoft Edge, Windows 11, LiteLLM
CyberSecurity News

Pwn2Own Berlin 2026: Critical Flaws Hacked in Microsoft Edge, Windows 11, LiteLLM

Key Takeaways Pwn2Own Berlin 2026’s opening day saw significant zero-day exploits across major software and emerging AI platforms. Researchers successfully breached Microsoft Edge, Windows 11,...

Marcus Rodriguez
Marcus Rodriguez
May 15, 2026 4 Min Read
79 0

Key Takeaways

  • Pwn2Own Berlin 2026’s opening day saw significant zero-day exploits across major software and emerging AI platforms.
  • Researchers successfully breached Microsoft Edge, Windows 11, and LiteLLM, uncovering 24 unique vulnerabilities and earning over half a million dollars.
  • The event underscores the increasing vulnerability of AI ecosystems and core enterprise technologies to sophisticated, multi-stage attacks.
  • Multiple vendors, including Microsoft, OpenAI, and NVIDIA, are affected by these newly discovered critical flaws.

The Pwn2Own Berlin 2026 competition kicked off with a flurry of successful zero-day exploits, demonstrating critical vulnerabilities in widely used software and cutting-edge artificial intelligence platforms. On its inaugural day, security researchers achieved breakthroughs against Microsoft Edge, Windows 11, and LiteLLM, collectively identifying 24 distinct vulnerabilities and securing payouts totaling $523,000.

Table Of Content

  • Key Takeaways
  • Edge Sandbox Escape
  • Windows 11 Privilege Escalations
  • LiteLLM Exploited
  • AI and Developer Tools Under Pressure
  • What You Should Do

These initial findings from the competition underscore a critical shift in the cybersecurity landscape: sophisticated, chained attacks are increasingly targeting both established enterprise technologies and the rapidly evolving AI ecosystem.

Edge Sandbox Escape

One of the most impactful demonstrations came from Orange Tsai of the DEVCORE Research Team, who successfully executed a complex sandbox escape against Microsoft Edge. This exploit was particularly notable for chaining together four separate logic vulnerabilities, transforming what might otherwise be minor flaws into a full system compromise. The advanced technique earned DEVCORE $175,000 and 17.5 Master of Pwn points, positioning them as early leaders in the competition. This attack serves as a stark reminder that even modern browser security mechanisms can be bypassed when multiple weaknesses are strategically combined.

Windows 11 Privilege Escalations

Microsoft Windows 11 also proved to be a significant target, experiencing several successful privilege escalation attacks throughout the day. Researchers demonstrated various attack vectors, including those leveraging heap-based buffer overflows and use-after-free vulnerabilities. Notably, Angelboy and TwinkleStar03, also from DEVCORE, exploited an improper access control flaw to achieve elevated privileges. These repeated compromises highlight that even mature operating systems like Windows 11 remain susceptible to memory corruption and access control issues.

LiteLLM Exploited

AI infrastructure faced intense scrutiny, with LiteLLM succumbing to a full-chain exploit orchestrated by researcher k3vg3n. This attack combined three distinct vulnerabilities, including Server-Side Request Forgery (SSRF) and code injection, ultimately leading to a complete system takeover. The exploit secured $40,000 for k3vg3n and critically illuminated how AI frameworks, particularly those interacting with external inputs and APIs, can introduce severe security gaps if not robustly hardened.

AI and Developer Tools Under Pressure

Beyond LiteLLM, other AI-focused targets also experienced successful compromises. Compass Security researchers leveraged a CWE-150 flaw to exploit OpenAI Codex. NVIDIA’s Megatron Bridge was breached multiple times due to overly permissive allow lists and path-traversal vulnerabilities. Concurrently, IBM X-Force researchers successfully exploited a single bug within the NV Container Toolkit. These discoveries collectively reinforce concerns about the security maturity of AI and developer tooling ecosystems, suggesting ongoing challenges in secure design and resilience against threats.

Not every attempt at Pwn2Own Berlin 2026 succeeded. Several researchers failed to exploit targets such as OpenAI Codex and Oracle Autonomous AI Database within the allocated time. Additionally, multiple “collision” cases were reported, where working exploits relied on previously known vulnerabilities. While these cases still garnered rewards, they underscore a persistent issue: organizations’ failure to promptly patch known security flaws.

According to the Zero Day Initiative, the results from Day One of Pwn2Own Berlin 2026 signal a significant shift in the threat landscape. Attackers are no longer exclusively focused on traditional software but are now actively targeting AI platforms, inference engines, and developer tools. With DEVCORE currently leading the competition and more high-value targets slated for the coming days, the event is poised to uncover even deeper vulnerabilities, serving as a critical warning to vendors and enterprises alike.

What You Should Do

  • Prioritize immediate patching for all Microsoft Edge and Windows 11 systems as updates become available, particularly for privilege escalation and sandbox escape vulnerabilities.
  • For organizations utilizing LiteLLM or similar AI frameworks, conduct thorough security audits, focusing on input validation, API security, and access control mechanisms to mitigate SSRF and code injection risks.
  • Review and harden configurations for AI and developer tools like OpenAI Codex, NVIDIA Megatron Bridge, and NV Container Toolkit, paying close attention to allow lists, path traversal protections, and overall access control.
  • Implement a robust vulnerability management program to ensure prompt application of patches for all known security flaws, even those identified as “collisions” in competitions like Pwn2Own.
  • Adopt a defense-in-depth strategy, including network segmentation, endpoint detection and response (EDR), and continuous monitoring, to detect and respond to sophisticated, chained attacks.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachExploitPatchSecurityThreatzero-day

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

OrBit Rootkit Steals SSH and Sudo Credentials From Linux Systems

Next Post

Critical Flaw in Microsoft 365 OAuth Lets Attackers Steal Tokens

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Claude AI code enabled ransomware gang to steal LDAP passwords, backdoor VPNs
August 18, 2026
Pokémon Center Data Breach Exposes Customer PII to Hackers
August 18, 2026
Best Software-Defined Perimeter (SDP) Solutions of 2024
August 17, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us