Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Pwn2Own’s successful demonstrations show that exploitable weaknesses can exist in ordinary applications, enterprise systems, connected products, and the infrastructure behind AI tools. For developers, the practical lesson is to track and assess the components and systems their software depends on—not just the code they write. The competition offers concrete examples of attack paths in selected products, but its results are not a measure of how common insecure software is across the industry.

What Pwn2Own is—and what its results mean

Pwn2Own is a recurring security research competition in which researchers demonstrate vulnerabilities against selected products. The findings give vendors specific issues to investigate and an opportunity to fix them through coordinated disclosure. Trend Micro says the competition began in 2007 and now features three events annually: Trend Micro’s 2025 Berlin results.

A successful demonstration establishes that a particular attack worked under the competition’s rules and conditions. It does not establish that the vulnerability was exploited in the wild, or that the affected product represents its whole category. Targets and rules vary by event, so counts are best read as snapshots of the specific products and categories included.

How the targets have broadened

The events cover more than desktop applications. Pwn2Own Ireland 2025 included printers, network storage, smart-home and surveillance devices, networking equipment, smartphones, and wearables. The event reported 73 unique zero-day vulnerabilities across its consumer and connected-product categories, according to Trend Micro’s Ireland 2025 results.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Berlin has also expanded into AI systems. In 2025, its targets included AI infrastructure; the event reported 28 unique zero-days, seven of them in the AI category. The event also reported $1,078,750 in awards. These figures are specific to Pwn2Own Berlin 2025, as reported by Trend Micro.

Berlin 2026 included AI databases and coding agents alongside browsers, enterprise applications, servers, and other categories. TrendAI reported 47 unique zero-day vulnerabilities and $1,298,250 in prizes for that event. Its announcement described demonstrations involving chained bugs in Exchange and Edge, a SharePoint exploit, VMware ESXi memory corruption, and an NV Container Toolkit exploit. These are examples from the competition, not evidence that every deployment of those products is vulnerable or that the flaws were used outside the event. See TrendAI’s Berlin 2026 announcement.

The inaugural Pwn2Own Automotive reported 49 unique zero-days. The Zero Day Initiative reported that figure in 2025 for the event held in 2024: its event results. The Berlin, Ireland, and Automotive counts describe different years, target mixes, and rules; they should not be used to rank categories or infer a year-over-year change in security.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What developers can learn from the demonstrations

Know what is in the software you ship

An application’s attack surface includes more than first-party code. Libraries, frameworks, subsystems, developer toolkits, and infrastructure can all matter. Trend Micro’s State of AI Security Report recommends maintaining an inventory of software components, including third-party libraries and subsystems, and regularly assessing them. That inventory helps teams identify where a disclosed issue could affect their products and decide what needs review or remediation.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Include AI tooling and infrastructure in security reviews

AI features can depend on components beyond a model or user-facing application. Trend Micro’s 2025 report identifies developer toolkits, vector databases, and model-management frameworks among the AI targets. Berlin 2026’s inclusion of AI databases and coding agents reinforces the need to consider these systems when mapping dependencies and reviewing security—not to treat AI infrastructure as outside the software supply chain.

Look at the whole connected product

Ireland 2025’s range of targets is a reminder that risk can sit in the device, its software, its network-facing services, or the systems used to manage it. Product security reviews should reflect the actual components and connections in the product rather than focus only on a desktop client or application layer.

Treat a demonstration as a prompt for verification

When a competition reports a finding in a product or technology your team uses, establish whether your version and configuration are affected, check vendor advisories, and identify dependencies that might include the vulnerable component. The competition result itself is not a substitute for an advisory or a determination about your deployment.

How to interpret the numbers responsibly

  • Keep the event and year attached to each count. Berlin 2025 reported 28 unique zero-days; Berlin 2026 reported 47; Ireland 2025 reported 73. They cover different targets and competition scopes.
  • Do not treat a higher count as proof of declining security. More categories, different products, and different rules can change what researchers test and what is counted.
  • Do not equate a contest result with real-world exploitation. The demonstrations show that specific attack paths worked in the competition; they do not establish use by attackers.
  • Separate event evidence from vendor claims. Statements about a vendor’s own products or protection timelines should be attributed to that vendor rather than treated as independent comparisons.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.