Researchers Cash In On Day One Of Pwn2Own Ireland
On the opening day of Pwn2Own Ireland 2026, running October 6–9 in Cork, Ireland, security researchers earned $388,500 after successfully exploiting 32 zero-day vulnerabilities. Competitors put 21 entries on stage across seven target categories, hacking Samsung's flagship Galaxy S26 twice along with smart home hubs, enterprise printers, an AI database, and an AI coding agent. The contest is organized by Trend Micro's Zero Day Initiative (ZDI), which gives affected vendors 90 days to patch before any technical details are disclosed publicly.
Incident Details
| Attribute | Value |
|---|---|
| Event | Pwn2Own Ireland 2026 |
| Organizer | Zero Day Initiative (ZDI / Trend Micro) |
| Location | Cork, Ireland |
| Dates | October 6–9, 2026 |
| Day One entries | 21 |
| Day One payout | $388,500 |
| Day One zero-days exploited | 32 |
| Categories | Mobile phones, printers, smart home, messaging apps, AI infrastructure, AI coding agents, wellness/healthcare devices |
| Disclosure window | 90 days (standard ZDI policy) |
| Prior year comparison | $1,024,750 awarded for 73 zero-days (Pwn2Own Ireland 2025) |
What Happened
Samsung Galaxy S26 Falls Twice
The marquee result of the day came against Samsung's new Galaxy S26 flagship, targeted in the contest's top-paying "Mobile Phone (Remote)" category. Interrupt Labs, Ikotas Labs, Inc., and Nguyen Thanh Dat of Viettel Cyber Security each took a run at the device, successfully exploiting it twice during the day. Nguyen Thanh Dat's chain used four bugs and earned $31,250, Interrupt Labs used four bugs for $15,750, and Ikotas Labs chained four bugs for $11,000. ZDI noted that several of the bugs used in these chains had already been reported to Samsung by other researchers — a "collision," in Pwn2Own terms — which reduces the payout but still counts toward the day's zero-day tally. Not every mobile attempt landed: White Noise Club (Mikhail Evdokimov, Polina Smirnova, Mate Zombor) ran out of time trying to exploit the Google Pixel 10.
Smart Home And IoT Devices Breached
Smart home gear took heavy damage. VinSOC fielded multiple squads and emerged as the day's leading team, chaining seven zero-day bugs against the Philips Hue Bridge Pro for $40,000. Two further teams — Out of Bounds and Joohyun Park of Xint — also cracked the Hue Bridge Pro using bug chains that partially overlapped with previously known issues, earning $12,000 and $6,000 respectively. The Sonos Era 300 smart speaker was exploited twice: once by researcher @_McCaulay using an out-of-bounds write plus a format-string bug for the full $50,000, and again by VinSOC (linhlhq, Son Dinh) via a two-bug collision chain worth $17,500.
AI Infrastructure And Coding Agents Targeted
The contest's newer AI-focused categories produced some of the day's more consequential findings. VinSOC (Nam Nguyen, Thanh Vu, Tin Huynh) chained five zero-days against Oracle's Autonomous AI Database for $40,000. LiteLLM, a widely used open-source LLM gateway, was exploited twice — by Taisic Yun of Xint ($40,000, improper input validation plus code injection) and by Out of Bounds ($15,000, a four-bug collision chain). Ikotas Labs, Inc. also broke OpenAI's Codex cloud coding agent with a single argument-injection flaw, worth $40,000 — a reminder that AI agents which execute commands or shell out to tooling remain a soft target for injection-class bugs.
Printers And Wearables
Enterprise printers remained a reliable source of bugs: Sina Kheirkhah of Summoning Team used a single argument-injection flaw to take $10,000 from a Lexmark CX532adwe, while Thanh Do of Team Confused used a single use-after-free for $20,000 against the same model. BleepingComputer also reported a successful hack of a Canon imageFORCE 1643F multifunction printer. In the new wellness category, Interrupt Labs combined an out-of-bounds read and write to compromise the Garmin Index BPM blood-pressure monitor for $20,000, while Aaron Christophel of Summoning Team ran out of time on the same target.
Unsuccessful Attempts
Five of the day's 21 entries failed to score, all due to exploits not completing within the allotted time rather than vendor mitigations blocking them outright: Ikotas Labs, Inc. against a Brother MFC-L8970CDW printer, Team T-X Lab against a Lexmark CX532adwe, White Noise Club against the Google Pixel 10, Aaron Christophel against the Garmin Index BPM, and VinSOC against the Chroma vector database.
Impact Assessment
| Impact Area | Description |
|---|---|
| Mobile devices | Samsung's unreleased Galaxy S26 security posture is now under vendor remediation across at least three independent exploit chains |
| Smart home / IoT | Philips Hue Bridge Pro and Sonos Era 300 both had multiple independent chains land, suggesting systemic weaknesses rather than one-off bugs |
| AI infrastructure | Oracle Autonomous AI Database and LiteLLM compromises show AI-adjacent infrastructure is now a first-class Pwn2Own target, not an afterthought |
| AI coding agents | A single argument-injection bug fully compromising OpenAI Codex highlights how command-execution surfaces in agentic tooling remain under-hardened |
| Enterprise printers | Lexmark and Canon multifunction devices again proved exploitable, continuing a multi-year Pwn2Own pattern for this device class |
| Disclosure timeline | All 32 bugs enter ZDI's standard 90-day coordinated disclosure process; vendors must patch before technical write-ups go public |
Recommendations
For IT Administrators
- Treat Samsung, Philips (Hue), Sonos, Lexmark, Canon, and Garmin as on watch for emergency patches over the next 90 days and prioritize their update channels.
- Confirm auto-update is enabled on managed printer fleets (Lexmark CX532adwe, Canon imageFORCE 1643F) and smart-home hub firmware (Philips Hue Bridge Pro).
- Inventory any Samsung Galaxy S26 devices in BYOD or corporate-issued fleets so patches can be pushed as soon as Samsung ships fixes.
For Security Teams
- Subscribe to ZDI's advisory feed and Trend Micro's disclosure calendar to track when the 90-day window closes on each of the 32 bugs disclosed this week.
- If running LiteLLM or Oracle Autonomous AI Database in production, review deployment configs for the input-validation and chaining weaknesses described by ZDI once technical details publish, and apply vendor patches immediately on release.
- Audit any internal use of OpenAI Codex or similar coding agents for argument-injection exposure — restrict the commands/arguments these agents can pass to underlying shells or APIs.
For End Users
- Install Samsung, Sonos, Philips Hue, and Garmin firmware/app updates promptly once released — Pwn2Own disclosures are a reliable predictor of a near-term patch cycle.
- Avoid exposing smart home hubs (Hue Bridge Pro) or Sonos speakers directly to the internet; keep them on segmented home networks where possible.
Key Takeaways
- Day one of Pwn2Own Ireland 2026 produced 32 zero-days and $388,500 in payouts across 21 entries, with 14 successful attempts and 5 failures.
- Samsung's Galaxy S26 flagship was exploited twice, by Interrupt Labs, Ikotas Labs, and Viettel Cyber Security's Nguyen Thanh Dat, though several underlying bugs were already known to Samsung.
- VinSOC led the day's Master of Pwn standings after chaining bugs against both the Philips Hue Bridge Pro and Oracle's Autonomous AI Database for $40,000 apiece.
- AI infrastructure and agentic coding tools (LiteLLM, Oracle AI Database, OpenAI Codex) are now squarely in scope at Pwn2Own, and a single argument-injection bug was enough to fully compromise Codex.
- All disclosed vulnerabilities fall under ZDI's standard 90-day coordinated disclosure policy — affected vendors must ship patches before public write-ups appear.
- The contest continues through October 9, with further attempts expected against the Galaxy S26, Google Pixel 10, and remaining smart home, AI, and printer targets.