Microsoft Exchange Windows 11 Zero-Day Exploits Pwn2Own | MSSP Advisory
High
DateMay 15, 2026
📋Executive Summary
Pwn2Own Berlin 2026 competitors exploited 15 zero-day vulnerabilities across Windows 11, Microsoft Exchange, and Red Hat Enterprise Linux, earning $385,750 in bounties. The successful exploits demonstrate active zero-day vulnerabilities in core business systems that Microsoft and Red Hat have not yet patched. These are proof-of-concept attacks that confirm exploitable flaws exist in production environments.
⚠️Why It Matters for MSSPs
Your RMM agents run on Windows endpoints that may contain these unpatched vulnerabilities, and compromised Windows systems can pivot to your management infrastructure. Every client running Exchange or Windows 11 sits exposed to attack methods that work right now, and you have no patches to deploy because Microsoft does not know about some of these flaws yet.
📬
Get notified when client-ready advisories like this are published each week.
Join the MSSP Watchlist →🏷️Threat Category
Zero-Day
Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.