Pwn2Own Berlin 2026 Day Two Reveals Multiple Zero-Day Vulnerabilities
Security researchers at the Pwn2Own Berlin 2026 competition demonstrated 15 new zero-day vulnerabilities across various enterprise software and operating systems, including Microsoft Exchange, Windows 11, and Red Hat Enterprise Linux.

English Brief
Security researchers at the Pwn2Own Berlin 2026 competition demonstrated 15 new zero-day vulnerabilities across various enterprise software and operating systems, including Microsoft Exchange, Windows 11, and Red Hat Enterprise Linux.
الموجز العربي
اليوم الثاني من مسابقة Pwn2Own برلين 2026 يكشف عن ثغرات أمنية جديدة
كشف باحثون أمنيون في مسابقة Pwn2Own برلين 2026 عن 15 ثغرة أمنية جديدة في برمجيات وأنظمة تشغيل مؤسسية، بما في ذلك مايكروسوفت إكستشينج، وويندوز 11، ونظام ريد هات للمؤسسات.
- 1Monitor vendor portals (Microsoft, Red Hat, NVIDIA) for specific security advisories.
- 2Patch identified software to the latest version immediately upon release.
- 3Restrict administrative access to internet-facing services like Microsoft Exchange.
English Advisory
// Intelligence Summary
During the second day of Pwn2Own Berlin 2026, security researchers demonstrated 15 unique zero-day exploits targeting enterprise software and platforms. Notable successes included a 3-bug chain achieving Remote Code Execution (RCE) on Microsoft Exchange, privilege escalation on Windows 11, and exploits against AI-related tools like Cursor, Ollama, and LiteLLM.
التقرير العربي
// ملخص استخباراتي
خلال اليوم الثاني من مسابقة Pwn2Own برلين 2026، استعرض باحثون أمنيون 15 ثغرة أمنية جديدة من نوع (Zero-Day) تستهدف برمجيات ومنصات مؤسسية. تضمنت النجاحات البارزة سلسلة من ثلاث ثغرات أدت إلى تنفيذ تعليمات برمجية عن بعد (RCE) بصلاحيات SYSTEM على Microsoft Exchange، وتصعيد صلاحيات على Windows 11، بالإضافة إلى ثغرات في أدوات الذكاء الاصطناعي مثل Cursor وOllama وLiteLLM.
// Technical Context
The vulnerabilities disclosed represent a range of exploit primitives including use-after-free, code injection, and integer overflow. Specifically, the DEVCORE research team successfully chained three distinct vulnerabilities to achieve SYSTEM-level RCE on Microsoft Exchange. Other findings involve local privilege escalation on RHEL, as well as code execution vectors identified in AI agents and containerization tools.
// السياق الفني
تتضمن الثغرات المكتشفة مجموعة متنوعة من الأخطاء البرمجية بما في ذلك (Use-After-Free)، وحقن الأكواد (Code Injection)، وتجاوز سعة الأعداد الصحيحة (Integer Overflow). أثبت فريق DEVCORE قدرته على دمج ثلاث ثغرات منفصلة لتحقيق تنفيذ برمجيات عن بعد على Exchange. كما شملت النتائج الأخرى تصعيد صلاحيات محلي على RHEL، ونواقل تنفيذ برمجيات في وكلاء الذكاء الاصطناعي وأدوات الحاويات.
// Exposure Notes
These vulnerabilities currently exist as zero-days presented in a controlled environment. Enterprises utilizing Microsoft Exchange, NVIDIA Container Toolkit, and AI/LLM development tools should monitor vendor security bulletins for forthcoming patches, as details of these exploits are likely to be disseminated to vendors for remediation.
// ملاحظات التعرض
هذه الثغرات حالياً في مرحلة الكشف المبدئي ضمن بيئة المسابقة. يجب على المؤسسات التي تستخدم Microsoft Exchange، وNVIDIA Container Toolkit، وأدوات تطوير الذكاء الاصطناعي مراقبة نشرات الأمان الخاصة بالموردين للحصول على التحديثات الأمنية فور صدورها.
// Defensive Priority
Organizations should prioritize the identification and hardening of internet-facing Microsoft Exchange servers. Additionally, security teams should review the configurations of containerization environments (e.g., NVIDIA Container Toolkit) and monitor the supply chain for AI development tools to mitigate risks associated with code injection and privilege escalation.
// أولوية الدفاع
يجب على المؤسسات إعطاء الأولوية لتحديد وتأمين خوادم Microsoft Exchange المواجهة للإنترنت. بالإضافة إلى ذلك، يجب على الفرق الأمنية مراجعة إعدادات بيئات الحاويات (مثل NVIDIA Container Toolkit) ومراقبة سلسلة التوريد الخاصة بأدوات تطوير الذكاء الاصطناعي لتقليل المخاطر المرتبطة بحقن الأكواد وتصعيد الصلاحيات.
Mitigation Checklist
- 1Monitor vendor portals (Microsoft, Red Hat, NVIDIA) for specific security advisories.
- 2Patch identified software to the latest version immediately upon release.
- 3Restrict administrative access to internet-facing services like Microsoft Exchange.
- 4Review container permissions and isolate AI-development workloads until updates are applied.
قائمة إجراءات التخفيف
- 1راقب بوابات الموردين (Microsoft, Red Hat, NVIDIA) للحصول على التحديثات الأمنية.
- 2قم بتحديث البرمجيات المتأثرة إلى أحدث إصدار فور توفره.
- 3قيد الوصول الإداري إلى الخدمات المواجهة للإنترنت مثل Microsoft Exchange.
- 4راجع صلاحيات الحاويات واعزل بيئات عمل تطوير الذكاء الاصطناعي حتى يتم تطبيق التحديثات.
- Source: Zero Day Initiative
# Checklist for securing affected systems:
# 1. Monitor vendor portals (Microsoft, Red Hat, NVIDIA) for specific security advisories.
# 2. Patch identified software to the latest version immediately upon release.
# 3. Restrict administrative access to internet-facing services like Microsoft Exchange.
# 4. Review container permissions and isolate AI-development workloads until updates are applied.