Pwn2Own Ireland 2026: 32 zero-days exploited on day one

Pwn2Own Ireland 2026: 32 zero-days exploited on day one

Security researchers exploited 32 zero-day vulnerabilities on the opening day of Pwn2Own Ireland 2026 and earned $388,500 in prize money. The Samsung Galaxy S26 was compromised twice.

Pwn2Own is a hacking contest run by Trend Micro's Zero Day Initiative (ZDI). Its purpose is to find unknown flaws in popular products before threat actors discover and abuse them. When a bug is exploited on stage, the affected vendor has 90 days to ship a fix. After that, ZDI publishes the details.

Seven categories, including wellness devices

This year's Irish edition covers seven product categories. Mobile phones are the most visible, with the Apple iPhone 17, Samsung Galaxy S26 and Google Pixel 10 as targets. The other categories are printers, smart home devices, messaging apps, AI infrastructure and AI coding apps.

There is also a new category for wellness healthcare devices. It is the first time competitors are attempting to break into this type of product at the event.

Galaxy S26 falls twice

The Galaxy S26 was the main mobile result of the day. Interrupt Labs, Ikotas Labs, and Nguyen Thanh Dat of Viettel Cyber Security were behind the attacks on Samsung's flagship.

The phone attacks did not count as entirely new findings, though. In each of these challenges, some of the bugs used were already known to the vendor. Pwn2Own treats overlaps like this as collisions. A successful exploit still counts, but researchers get less credit when part of the chain was not new.

The Google Pixel 10 held up on day one. Mikhail Evdokimov, Polina Smirnova, and Mate Zombor of White Noise Club tried to compromise it but could not get their exploit working within the time limit.

VinSOC leads with two long exploit chains

Vũ Chí Thành and Huỳnh Đức Tin of VinSOC finished the day at the top of the leaderboard. Their two entries both relied on long chains of previously unknown flaws.

The first chain linked seven zero-days to take over a Philips Hue Bridge Pro, a hub for controlling smart lighting. It earned the pair $40,000. They won another $40,000 for a chain of five zero-days against the Oracle Autonomous AI Database.

Chains of this length show how much effort goes into a single successful attack. Researchers often need several bugs, each covering one step, to move from initial access to full control of a device.

AI tools, printers and a smart speaker

Several other products were compromised over the course of the day:

  • LiteLLM: researchers demonstrated zero-days in this AI infrastructure software.
  • OpenAI Codex: the cloud-based AI coding agent was compromised through a single argument-injection bug.
  • Lexmark CX532adwe and Canon imageFORCE 1643F: both multifunction printers were hacked.
  • Sonos Era 300: a chain of four vulnerabilities was used to take over the smart speaker, which has been compromised at the event before.

The Codex result is notable for how little it took. While other teams needed five or seven chained bugs, a single argument-injection flaw was enough against the coding agent.

What's next in the contest

The second day brings more attempts against AI infrastructure, printers, smart home products and wellness devices. In the mobile category, the Samsung Galaxy S26 and Google Pixel 10 are on the schedule again.

On the third and final day, competitors will make further attempts against both flagship phones, along with several smart home, AI infrastructure and printer targets.

Last year's Pwn2Own Ireland ended with $1,024,750 paid out for 73 zero-days. Summoning Team took $187,500 of that after hacking the Samsung Galaxy S25, the Synology DiskStation DS925+ NAS, the Home Assistant Green, the Synology ActiveProtect Appliance DP320 NAS drive, the Synology CC400W camera, and the QNAP TS-453E NAS.

Our Take

At 32 zero-days in a single day, the 2026 contest is already close to half of last year's total of 73, with two days still to go. It is too early to say whether the final count will be higher. The pace suggests, though, that consumer and enterprise products remain full of exploitable flaws.

AI products deserve the most attention. LiteLLM, the Oracle Autonomous AI Database and OpenAI Codex were all compromised on day one. Codex fell to just one bug. This fits a wider pattern we have covered, with attacks on AI systems outpacing how ready many organisations are to defend them. AI tooling is being deployed quickly, and its security is clearly still maturing.

For defenders, the practical point is the 90-day disclosure window. Patches for these bugs should arrive in the coming months, and they are worth tracking closely. Exploitation is speeding up, and vulnerability disclosures are rising, so the gap between public disclosure and real-world abuse may keep shrinking.

It will be worth watching whether the Pixel 10 survives the remaining attempts. The first results from the new wellness category should also show how well healthcare devices hold up under expert scrutiny.