Pwn2Own Berlin 2026: 47 Zero-Days, $1,298,250 in Rewards

The results are in. Pwn2Own Berlin 2026 has wrapped up, and the numbers deserve serious attention.

47 zero-day vulnerabilities successfully demonstrated. $1,298,250 paid out to elite security researchers. Targets ranged from operating systems and browsers to virtualization platforms, AI infrastructure, and enterprise applications.

Let that sink in.

What Pwn2Own Actually Represents

Pwn2Own is not just a hacking competition — it is the most rigorous stress test the security industry runs. Organized by Trend Micro's Zero Day Initiative (ZDI), it gathers the world's top offensive researchers under controlled conditions to prove real-world exploitability against fully patched software.

Every successful exploit represents a vulnerability that: Existed in software millions of organizations rely on today Was completely unknown to the vendor until that moment Could have been silently weaponized by a nation-state actor or a ransomware group

When researchers land the exploit on stage, responsible disclosure begins immediately.

$1,298,250: A Feature, Not a Bug

Some question why vendors pay over a million dollars to people who break their software.

The answer is straightforward: the alternative costs far more. The average data breach reached $4.88M in 2025 (IBM). A single unpatched hypervisor or browser zero-day can give attackers full access to an enterprise environment. Structured programs like ZDI create a legitimate economic incentive to report — rather than sell on dark web markets or exploit silently.

Berlin 2026: What Was Targeted?

This year's competition featured exploitation across several high-value categories: • AI and ML inference platforms — a rapidly expanding attack surface • Virtualization and container escape — always high stakes • Browsers (Chrome, Firefox, Edge) — the classic gateway • Enterprise applications and cloud platforms • OS privilege escalation chains

The breadth mirrors how modern attackers operate: chain a browser bug with a kernel escalation, and you own an entire domain from a single phishing email.

Key Takeaways for Security Teams

Patch velocity matters. When ZDI publishes results, deploy fixes fast. Defense in depth is non-negotiable. No single control stops a zero-day adversary. Support offensive research. Advocate for bug bounty programs and VDPs at your org. Read ZDI post-patch advisories — invaluable for building precise detection rules.

Those 47 zero-days existed before the competition started. Pwn2Own simply ensures the right people find them first.

Follow for threat intelligence insights and practical cybersecurity content.

Turn the analysis into a plan

The gap between knowing the risk and closing it is a purchase order and a weekend.

We specify, source and deploy the equipment that closes it — firewalls, segmentation, secure remote access — and we support it afterwards.