Security researchers collectively uncovered 32 zero-day vulnerabilities on the first day of the Pwn2Own Ireland 2026 competition, earning a total of $388,500. The event, organized by the Zero Day Initiative (ZDI), aims to identify critical flaws in various products before malicious actors can exploit them.
A significant highlight of the first day involved successful attacks against the Samsung Galaxy S26 flagship smartphone, which was compromised twice. Teams from Interrupt Labs, Ikotas Labs, and Nguyen Thanh Dat of Viettel Cyber Security were responsible for these exploits. It was noted that some of the vulnerabilities used in these challenges were already known to the vendor.
The competition features seven distinct categories: mobile phones (including the Apple iPhone 17, Samsung Galaxy S26, and Google Pixel 10), printers, smart home devices, messaging apps, AI infrastructure, AI coding apps, and a new category for wellness healthcare devices.
V Ch Th nh and Hu nh c Tin of VinSOC topped the leaderboard, securing $40,000 for chaining seven zero-days to exploit a Philips Hue Bridge Pro smart lighting hub. They earned an additional $40,000 by using a five zero-day exploit chain against the Oracle Autonomous AI Database.
Other successful exploits included demonstrating LiteLLM zero-days, compromising Lexmark CX532adwe and Canon imageFORCE 1643F multifunction printers, and taking down the OpenAI Codex cloud-based AI coding agent with a single argument-injection bug. Researchers also exploited four vulnerabilities to compromise a Sonos Era 300 smart speaker.
Not all attempts were successful; Mikhail Evdokimov, Polina Smirnova, and Mate Zombor of White Noise Club targeted the Google Pixel 10 but were unable to execute their exploit within the allocated time.
Following the disclosure of these flaws at Pwn2Own, affected vendors are given a 90-day window to release security updates before Trend Micro's ZDI publicly discloses the vulnerabilities.
The competition is scheduled to continue, with hackers targeting devices in the AI infrastructure, printers, smart home, and wellness categories on the second day, alongside further attempts on the Samsung Galaxy S26 and Google Pixel 10. The third day will see additional attempts against the Google Pixel 10 and Samsung Galaxy S26, as well as various smart home, AI infrastructure, and printer devices.
Last year's Pwn2Own Ireland event saw security researchers earn $1,024,750 for uncovering 73 zero-day flaws. The Summoning Team, for instance, collected $187,500 after successfully hacking the Samsung Galaxy S25, Synology DiskStation DS925+ NAS, Home Assistant Green, Synology ActiveProtect Appliance DP320 NAS drive, Synology CC400W camera, and QNAP TS-453E NAS.






