Pwn2Own Ireland Day One Yields 32 Zero-Days
Researchers exploited 32 zero-days at Pwn2Own Ireland 2026, targeting phones, printers, smart home hubs and AI infrastructure for $388,500.
The Zero Day Initiative's Pwn2Own Ireland 2026 contest opened with researchers exploiting 32 zero-days in a single day, with Samsung's Galaxy S26 falling twice and VinSOC's team topping the leaderboard. The competition targets products across seven categories, from flagship phones to AI databases and, for the first time, wellness healthcare devices.
BleepingComputer reported that the first day's confirmed exploits carried a combined prize total of $388,500. That figure covers successful demonstrations on mobile handsets, printers, smart home hardware, AI coding agents and a database platform, according to the outlet's account of the day's events.
Seven target categories, one new
Pwn2Own Ireland 2026 competitors are working against target products in seven categories. Mobile phones in scope include the Apple iPhone 17, Samsung Galaxy S26 and Google Pixel 10. Other categories cover printers, smart home devices, messaging apps, AI infrastructure, AI coding apps and a new category focused on wellness healthcare devices.
The addition of the wellness category means researchers will attempt to exploit connected healthcare hardware alongside more established targets. BleepingComputer's report did not detail which specific wellness devices are in scope or how many entries are expected in that category across the three days.
Samsung's flagship falls twice
The headline result of day one involved Interrupt Labs, Ikotas Labs and Nguyen Thanh Dat of Viettel Cyber Security, each of whom hacked the Galaxy S26. According to BleepingComputer, some of the bugs exploited in each challenge were already known to the vendor.
The Galaxy S26 is one of three mobile handsets listed in the mobile phones category, alongside the iPhone 17 and Pixel 10. Its double exploitation on day one means two separate successful demonstrations were recorded against the device before the competition moved into its second day.
Google's Pixel 10 also drew attention on day one, though not for a successful result. Mikhail Evdokimov, Polina Smirnova and Mate Zombor of White Noise Club targeted the Pixel 10 but could not get their exploit to work within the allotted time, per BleepingComputer's report. The same outlet noted the Pixel 10 is scheduled to be targeted again on both the second and third days of the contest.
VinSOC's chained exploits and the leaderboard
Vũ Chí Thành and Huỳnh Đức Tin of VinSOC topped the leaderboard on day one, according to BleepingComputer. The pair won $40,000 after chaining seven zero-days to exploit a Philips Hue Bridge Pro smart lighting hub. They added a further $40,000 for a five zero-day exploit chain targeting the Oracle Autonomous AI Database.
The two efforts together represent twelve separate vulnerabilities surfaced by a single team in one day, split between a consumer smart lighting hub and an enterprise AI database platform.
The day's other demonstrated exploits, as reported by BleepingComputer, included:
- LiteLLM zero-days
- Hacks against the Lexmark CX532adwe and Canon imageFORCE 1643F multifunction printers
- A single argument-injection bug that took down the OpenAI Codex cloud-based AI coding agent
- Four vulnerabilities exploited to compromise a Sonos Era 300 smart speaker
That list spans consumer hardware, enterprise printing equipment and cloud-based AI tooling, with the Codex result standing out for its reported economy of means: one argument-injection bug was enough to compromise the coding agent.
The 90-day disclosure clock
The Zero Day Initiative organises the competition to identify zero-day vulnerabilities in targeted devices before threat actors can exploit them. After flaws are exploited at Pwn2Own, vendors have 90 days to release security updates before Trend Micro's ZDI publicly discloses them.
The 90-day window applies to each exploited flaw individually, meaning the day-one results create a rolling set of disclosure deadlines for the affected vendors. BleepingComputer's report did not specify exact dates for any individual disclosure.
Day two and day three schedules
On the second day of the contest, hackers will again target devices in the AI infrastructure, printers, smart home and wellness categories, as well as the Samsung Galaxy S26 and the Google Pixel 10 in the mobile phones category.
On the third day, they will attempt to hack the Google Pixel 10 and Samsung Galaxy S26 flagships again, alongside multiple smart home, AI infrastructure and printer devices.
Both flagship Android devices therefore remain in scope for the remainder of the event, with the Galaxy S26 already the subject of two successful demonstrations and the Pixel 10 still awaiting a completed exploit after the White Noise Club team's attempt ran out of time.
How last year's event compared
During last year's Pwn2Own Ireland event, security researchers earned $1,024,750 for 73 zero-day flaws. Summoning Team collected $187,500 of that total after hacking the Samsung Galaxy S25, the Synology DiskStation DS925+ NAS, the Home Assistant Green, the Synology ActiveProtect Appliance DP320 NAS drive, the Synology CC400W camera and the QNAP TS-453E NAS.
The 2026 edition's day-one total of $388,500 and 32 zero-days is a partial figure, covering only the first of three days. The comparison with last year's full-event numbers is therefore incomplete, since the 2026 contest had two more days of scheduled challenges remaining when BleepingComputer published its day-one report.
What the day-one results leave open
Several questions remain unresolved by the day-one coverage. BleepingComputer did not specify the prize amounts attached to the individual Samsung Galaxy S26 exploits, the identity of the vendors affected by the LiteLLM zero-days, or the value of the awards for the printer, Codex and Sonos demonstrations.
The outlet also did not state how many of the 32 zero-days were duplicates of known issues versus entirely new discoveries, beyond noting that some bugs in the Samsung challenges were already known to the vendor. No individual CVE identifiers were included in the report.
What is clear from the published account is the breadth of the first day's targets: mobile phones, smart home hubs and speakers, multifunction printers, an AI coding agent and an AI database. The contest continues with the same categories scheduled for days two and three.
Why it matters
For the vendors whose products were exploited, the day-one results set a 90-day clock running toward public disclosure, which could mean patch work spread across phones, printers, smart home devices and AI services in a compressed window. Businesses that deploy any of the targeted products may want to track vendor advisories over the coming months rather than waiting for disclosure deadlines to pass.
The Codex and Oracle Autonomous AI Database results suggest that AI-focused tooling is being treated as a viable target by researchers, which could indicate that defenders should expect the same adversarial attention on AI infrastructure that other networked software already receives. And the inclusion of a wellness healthcare category points to connected health devices being brought into the same testing regime as phones and printers — a development worth watching for anyone responsible for securing those devices in clinical or home settings.
Sources
- BleepingComputer Original source
- target products in seven categories Also reporting
- Interrupt Labs Also reporting
- Ikotas Labs Also reporting
- Nguyen Thanh Dat of Viettel Cyber Security Also reporting
- the bugs Also reporting
- were already known Also reporting
Continue Reading
Outlook Adds Two More Blocked File Types
Microsoft will block .msix and .msixbundle attachments in New Outlook for Windows and Outlook on the Web starting in November 2026.
Red Hat Batch-Fixes 400 Open-Source Flaws
Red Hat's Lightwell Clearinghouse exits pilot after remediating over 400 novel vulnerabilities in foundational Java libraries since June.
September M&A: 39 Deals Reshape Security
Cybersecurity M&A stayed busy in September 2026 with 39 announced deals, spanning OT security, AI governance and offensive testing.