Pwn2Own Berlin 2026, Day Three: DEVCORE Crowned Master of Pwn, $1.298 Million Total

2026-05-17T02:51:46Zf3621516b8f2d4534c28d2623c9292075303b7aa26e8854277de0ec1f61aff65
cisco-sd-wancve-2026-20182cve-2026-42897ghostwritergreenplasmakazuarknown-exploited-vulnerabilitiesmicrosoft-exchangeopenaipwn2ownsupply-chaintanstackturlayellowkeyzero-day

What happened

SecurityAffairs roundup: Pwn2Own Berlin 2026 concluded with researchers disclosing dozens of zero-days and $1.29M in payouts, while multiple high‑impact incidents and disclosures surfaced across the week. CISA added two actively exploited/known‑exploited flaws to its KEV catalog — Microsoft Exchange Server CVE-2026-42897 (CVSS 8.1, active exploitation) and Cisco Catalyst SD‑WAN CVE-2026-20182 (CVSS 10.0). Threat activity included Russia‑linked Turla evolving the Kazuar backdoor into a stealthy P2P botnet for long‑term access, resumed Ghostwriter (FrostyNeighbor) operations targeting Ukrainian‑

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
f3621516b8f2d4534c28d2623c9292075303b7aa26e8854277de0ec1f61aff65
Enrichment time
2026-05-17T02:51:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.