Pwn2Own Ireland 2026 Day One: 32 Zero-Days, $388,500 in Payouts

Researchers demonstrated 32 unique zero-day exploits on day one of Pwn2Own Ireland 2026, earning $388,500 against phones, routers, printers and AI platforms.
Table of Contents
    Add a header to begin generating the table of contents

    Researchers demonstrated 32 unique zero-day exploits on the first day of Pwn2Own Ireland 2026, earning $388,500 in payouts. The targets ranged from smartphones and smart-home hubs to printers and AI infrastructure.

    Day One Results at Pwn2Own Ireland

    The contest’s first day produced 32 unique zero-day exploits against eight products. Researchers hacked the Samsung Galaxy S26 twice, along with the Philips Hue Bridge Pro, Oracle Autonomous AI Database, LiteLLM, Lexmark CX532adwe, Canon imageFORCE 1643F, the OpenAI Codex cloud coding agent and the Sonos Era 300. An attempt against the Google Pixel 10 failed.

    Days two and three of the event continue, so the totals for the full contest are not yet known.

    VinSOC Earns $80,000 With Two Multi-Bug Chains

    The team from VinSOC, made up of Vu Chi Thanh and Huynh Duc Tin, earned $80,000 on the day. They received $40,000 for a seven-bug chain against the Philips Hue Bridge Pro and another $40,000 for a five-bug chain against Oracle Autonomous AI Database. Both entries show how contest teams combine several smaller flaws into a single path to compromise.

    Single-Bug and Multi-Bug Attacks on OpenAI Codex and Sonos Era 300

    A single argument-injection bug was enough to take down OpenAI Codex, the cloud coding agent. The Sonos Era 300 fell to a different approach: researchers used four vulnerabilities against the speaker. The contrast between the two results shows the range of attack effort across the targets, from one flaw to a chain of several.

    Samsung Galaxy S26 Compromised Twice

    The Samsung Galaxy S26 was successfully attacked two times during the first day. Some of the bugs used against the phone were already known to the vendor, according to the contest reporting. The two successful Galaxy S26 attacks make the phone the only product compromised more than once on the opening day. The remaining seven successful targets were each compromised by a single entry, and the one attempt that failed was against a different phone, the Google Pixel 10.

    The failed Google Pixel 10 attempt was the one target where a contestant did not succeed on day one.

    Consumer Devices, Printers and AI Infrastructure in Scope

    The list of successful targets covers several product categories. Consumer and home devices included the Samsung Galaxy S26, Philips Hue Bridge Pro and Sonos Era 300. Office hardware included the Lexmark CX532adwe and Canon imageFORCE 1643F. Software and AI platforms included Oracle Autonomous AI Database, LiteLLM and OpenAI Codex.

    What the Results Mean for AI Platform Vendors

    Three of the day’s successful targets, Oracle Autonomous AI Database, LiteLLM and OpenAI Codex, are AI-related products. All three were compromised on the opening day, one of them through a single argument-injection bug. The affected vendors now have those findings in hand.

    The 90-Day Disclosure Window

    Pwn2Own gives vendors 90 days to patch the demonstrated flaws before they are disclosed publicly. That window now starts for the affected vendors, including Samsung, Philips, Oracle, Lexmark, Canon, OpenAI, Sonos and the maintainers of LiteLLM.

    During that period the exploit details are held by the vendors and the contest organizers rather than published. Dozens of unpatched flaws are now with vendors across consumer devices, printers and AI infrastructure.

    The remaining two days of the contest will add to the total. The day-one figures of 32 unique zero-days and $388,500 in payouts set the baseline for the rest of the event, and the final tally will show how many additional vulnerabilities move into the disclosure window.

    The contest record for day one stands at eight successful products, one failed attempt and 32 unique zero-day exploits. Vendors for the Samsung Galaxy S26, Philips Hue Bridge Pro, Oracle Autonomous AI Database, LiteLLM, Lexmark CX532adwe, Canon imageFORCE 1643F, OpenAI Codex and Sonos Era 300 each received a demonstrated attack on their product.

    Related Posts