Pwn2Own Ireland 2026 Day One Finds 32 Zero-Days

Security researchers at Pwn2Own Ireland 2026 in Cork exploited 32 unique zero-day vulnerabilities across smartphones, smart home devices, printers, databases and AI platforms on the opening day of the contest, earning a combined $388,500 in prizes[1][2][4]. Initial coverage from Infosecurity Magazine and other outlets emphasized the breadth of impacted technologies, from flagship phones and smart lighting to AI coding assistants and connected health devices[2][6]. The event, run by Trend Micro’s Zero Day Initiative (ZDI), is designed to surface critical flaws in widely deployed products before criminal actors can weaponize them[3][4].

According to Zero Day Initiative’s day-one results, 21 entries targeted categories ranging from Samsung’s Galaxy S26 and Google’s Pixel 10 to smart speakers, networked lighting, printers and health devices[3][9]. Researchers from Viettel Cyber Security, VinSOC, Interrupt Labs and other teams repeatedly compromised the Galaxy S26, sometimes chaining multiple previously unknown bugs in a single demonstration[3][4]. VinSOC researchers Vũ Chí Thành and Huỳnh Đức Tin disclosed seven zero-day flaws while breaking Philips Hue Bridge Pro in the Smart Home category, taking home $40,000 and four “Master of Pwn” points[2][3][9]. Other successful entries included a use-after-free exploit against a Lexmark CX532adwe printer, multi-bug chains against the Oracle Autonomous AI Database, an argument injection attack on OpenAI Codex, and out-of-bounds read and write bugs against the Garmin Index BPM smart blood pressure monitor[1][2].

ZDI’s rules mean that vendors whose products were compromised now have up to 90 days to develop and ship patches before technical details are published, giving defenders a narrow but crucial window to prepare[3][4]. Day-one write-ups describe only high-level bug classes—such as memory safety issues and logic flaws—without disclosing full exploit chains, affected firmware builds or configuration details, and no CVE identifiers or CVSS scores have yet been assigned to the newly found bugs in public advisories reviewed[1][3]. Samsung, Philips (Signify), Oracle, Lexmark, OpenAI, Garmin and other vendors are expected to release security advisories mapping these contest findings to formal vulnerability IDs in the coming weeks, following the standard coordinated disclosure process used across recent Pwn2Own events[3][5].

While the Pwn2Own rules prohibit immediate public release of exploit code, the demonstrations highlight how attackers could achieve remote code execution, data exfiltration or device takeover on consumer and enterprise networks if similar bugs are discovered independently outside the contest[1][6]. A successful compromise of a flagship smartphone such as the Galaxy S26 can provide persistent access to corporate email, messaging apps and multifactor authentication tokens, turning a personal device into a powerful foothold for lateral movement[4][6]. Exploits against smart home hubs, printers and connected medical devices underscore the risks of poorly segmented networks, where what appear to be low-value IoT endpoints can become stepping stones to more sensitive systems and data[1][5].

Enterprise defenders running the targeted products will not see patches immediately, but they can start preparing by tightening network segmentation for IoT and printer fleets, reviewing mobile device management policies, and monitoring vendor security portals for new firmware and software updates tied to Pwn2Own Ireland findings. Security teams should track future advisories from ZDI and vendors—along with any additions to CISA’s Known Exploited Vulnerabilities catalog—to quickly prioritize patching once CVE identifiers and severity scores become available. Until fixes land, organizations can reduce exposure by limiting external access to printers and smart home gear, enforcing strong mobile OS hardening baselines, and keeping a close eye on threat intelligence for signs that Pwn2Own-style exploit techniques are being adopted in real-world attacks.

References

  1. 32 Unique 0-Days Exploited in Samsung S26, Pixel 10, OpenAI Codex and Other Devices in Pwn2Own 2026
  2. Pwn2Own Hackers Find 32 Zero-Day Vulnerabilities on Day One
  3. Pwn2Own Ireland 2026 – Day One Results
  4. На Pwn2Own в Ирландии трижды взломали Galaxy S26 за $388 тыс и 32 0-day
  5. Cybersecurity News & Threat Intelligence – RootPwn
  6. News in the Security category
  7. TrendAI Zero Day Initiative (@thezdi) …

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply