Securityaffairs.Co Pwn2Own Berlin 2026: DEVCORE Wins with 47 Zero-Days and $1.29M in Payouts
Article Content
- •DEVCORE discovered 47 unique zero-days, earning $1.29 million in total payouts.
- •The competition included significant targets like SharePoint and ESXi, showcasing critical vulnerabilities.
- •Sina Kheirkhah earned $7,000 for exploiting Red Hat Linux with a combination of known and unknown bugs.
Pwn2Own Berlin 2026 concluded with DEVCORE being crowned Master of Pwn after discovering 47 unique zero-days, leading to total payouts of $1,298,250. The competition showcased significant vulnerabilities, including exploits targeting SharePoint and ESXi. Participants demonstrated various attack vectors, with DEVCORE dominating across categories. The event highlighted the ongoing threat landscape, as researchers exploited critical systems, including Red Hat Linux. The total amount awarded during the event reached $1,298,250, surpassing the million-dollar threshold. The event took place over three days, culminating on May 16, 2026, at OffensiveCon. The findings from Pwn2Own are crucial for organizations to enhance their security postures against emerging threats.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Red Heron Exploits Gitea RCE Flaw in Multinational Campaign A Chinese-speaking threat actor, tracked as Red Heron, exploited the CVE-2026-60004 remote code execution vulnerability in Gitea, compromising 1,386 instances across seven countries. The campaign involved source-code theft, credential collection, and lateral movement, affecting organizations in Canada, Argentina…