NEWS

Hackers exploit 32 zero-days on first day of Pwn2Own Ireland

Researchers earned $388,500 after exploiting 32 zero-days on day one of Pwn2Own Ireland 2026, hitting the Samsung Galaxy S26 twice.

Dylan H.

News Desk

October 6, 2026
7 min read
Hackers exploit 32 zero-days on first day of Pwn2Own Ireland

Researchers Cash In On Day One Of Pwn2Own Ireland

On the opening day of Pwn2Own Ireland 2026, running October 6–9 in Cork, Ireland, security researchers earned $388,500 after successfully exploiting 32 zero-day vulnerabilities. Competitors put 21 entries on stage across seven target categories, hacking Samsung's flagship Galaxy S26 twice along with smart home hubs, enterprise printers, an AI database, and an AI coding agent. The contest is organized by Trend Micro's Zero Day Initiative (ZDI), which gives affected vendors 90 days to patch before any technical details are disclosed publicly.


Incident Details

AttributeValue
EventPwn2Own Ireland 2026
OrganizerZero Day Initiative (ZDI / Trend Micro)
LocationCork, Ireland
DatesOctober 6–9, 2026
Day One entries21
Day One payout$388,500
Day One zero-days exploited32
CategoriesMobile phones, printers, smart home, messaging apps, AI infrastructure, AI coding agents, wellness/healthcare devices
Disclosure window90 days (standard ZDI policy)
Prior year comparison$1,024,750 awarded for 73 zero-days (Pwn2Own Ireland 2025)

What Happened

Samsung Galaxy S26 Falls Twice

The marquee result of the day came against Samsung's new Galaxy S26 flagship, targeted in the contest's top-paying "Mobile Phone (Remote)" category. Interrupt Labs, Ikotas Labs, Inc., and Nguyen Thanh Dat of Viettel Cyber Security each took a run at the device, successfully exploiting it twice during the day. Nguyen Thanh Dat's chain used four bugs and earned $31,250, Interrupt Labs used four bugs for $15,750, and Ikotas Labs chained four bugs for $11,000. ZDI noted that several of the bugs used in these chains had already been reported to Samsung by other researchers — a "collision," in Pwn2Own terms — which reduces the payout but still counts toward the day's zero-day tally. Not every mobile attempt landed: White Noise Club (Mikhail Evdokimov, Polina Smirnova, Mate Zombor) ran out of time trying to exploit the Google Pixel 10.

Smart Home And IoT Devices Breached

Smart home gear took heavy damage. VinSOC fielded multiple squads and emerged as the day's leading team, chaining seven zero-day bugs against the Philips Hue Bridge Pro for $40,000. Two further teams — Out of Bounds and Joohyun Park of Xint — also cracked the Hue Bridge Pro using bug chains that partially overlapped with previously known issues, earning $12,000 and $6,000 respectively. The Sonos Era 300 smart speaker was exploited twice: once by researcher @_McCaulay using an out-of-bounds write plus a format-string bug for the full $50,000, and again by VinSOC (linhlhq, Son Dinh) via a two-bug collision chain worth $17,500.

AI Infrastructure And Coding Agents Targeted

The contest's newer AI-focused categories produced some of the day's more consequential findings. VinSOC (Nam Nguyen, Thanh Vu, Tin Huynh) chained five zero-days against Oracle's Autonomous AI Database for $40,000. LiteLLM, a widely used open-source LLM gateway, was exploited twice — by Taisic Yun of Xint ($40,000, improper input validation plus code injection) and by Out of Bounds ($15,000, a four-bug collision chain). Ikotas Labs, Inc. also broke OpenAI's Codex cloud coding agent with a single argument-injection flaw, worth $40,000 — a reminder that AI agents which execute commands or shell out to tooling remain a soft target for injection-class bugs.

Printers And Wearables

Enterprise printers remained a reliable source of bugs: Sina Kheirkhah of Summoning Team used a single argument-injection flaw to take $10,000 from a Lexmark CX532adwe, while Thanh Do of Team Confused used a single use-after-free for $20,000 against the same model. BleepingComputer also reported a successful hack of a Canon imageFORCE 1643F multifunction printer. In the new wellness category, Interrupt Labs combined an out-of-bounds read and write to compromise the Garmin Index BPM blood-pressure monitor for $20,000, while Aaron Christophel of Summoning Team ran out of time on the same target.

Unsuccessful Attempts

Five of the day's 21 entries failed to score, all due to exploits not completing within the allotted time rather than vendor mitigations blocking them outright: Ikotas Labs, Inc. against a Brother MFC-L8970CDW printer, Team T-X Lab against a Lexmark CX532adwe, White Noise Club against the Google Pixel 10, Aaron Christophel against the Garmin Index BPM, and VinSOC against the Chroma vector database.

Impact Assessment

Impact AreaDescription
Mobile devicesSamsung's unreleased Galaxy S26 security posture is now under vendor remediation across at least three independent exploit chains
Smart home / IoTPhilips Hue Bridge Pro and Sonos Era 300 both had multiple independent chains land, suggesting systemic weaknesses rather than one-off bugs
AI infrastructureOracle Autonomous AI Database and LiteLLM compromises show AI-adjacent infrastructure is now a first-class Pwn2Own target, not an afterthought
AI coding agentsA single argument-injection bug fully compromising OpenAI Codex highlights how command-execution surfaces in agentic tooling remain under-hardened
Enterprise printersLexmark and Canon multifunction devices again proved exploitable, continuing a multi-year Pwn2Own pattern for this device class
Disclosure timelineAll 32 bugs enter ZDI's standard 90-day coordinated disclosure process; vendors must patch before technical write-ups go public

Recommendations

For IT Administrators

  • Treat Samsung, Philips (Hue), Sonos, Lexmark, Canon, and Garmin as on watch for emergency patches over the next 90 days and prioritize their update channels.
  • Confirm auto-update is enabled on managed printer fleets (Lexmark CX532adwe, Canon imageFORCE 1643F) and smart-home hub firmware (Philips Hue Bridge Pro).
  • Inventory any Samsung Galaxy S26 devices in BYOD or corporate-issued fleets so patches can be pushed as soon as Samsung ships fixes.

For Security Teams

  • Subscribe to ZDI's advisory feed and Trend Micro's disclosure calendar to track when the 90-day window closes on each of the 32 bugs disclosed this week.
  • If running LiteLLM or Oracle Autonomous AI Database in production, review deployment configs for the input-validation and chaining weaknesses described by ZDI once technical details publish, and apply vendor patches immediately on release.
  • Audit any internal use of OpenAI Codex or similar coding agents for argument-injection exposure — restrict the commands/arguments these agents can pass to underlying shells or APIs.

For End Users

  • Install Samsung, Sonos, Philips Hue, and Garmin firmware/app updates promptly once released — Pwn2Own disclosures are a reliable predictor of a near-term patch cycle.
  • Avoid exposing smart home hubs (Hue Bridge Pro) or Sonos speakers directly to the internet; keep them on segmented home networks where possible.

Key Takeaways

  1. Day one of Pwn2Own Ireland 2026 produced 32 zero-days and $388,500 in payouts across 21 entries, with 14 successful attempts and 5 failures.
  2. Samsung's Galaxy S26 flagship was exploited twice, by Interrupt Labs, Ikotas Labs, and Viettel Cyber Security's Nguyen Thanh Dat, though several underlying bugs were already known to Samsung.
  3. VinSOC led the day's Master of Pwn standings after chaining bugs against both the Philips Hue Bridge Pro and Oracle's Autonomous AI Database for $40,000 apiece.
  4. AI infrastructure and agentic coding tools (LiteLLM, Oracle AI Database, OpenAI Codex) are now squarely in scope at Pwn2Own, and a single argument-injection bug was enough to fully compromise Codex.
  5. All disclosed vulnerabilities fall under ZDI's standard 90-day coordinated disclosure policy — affected vendors must ship patches before public write-ups appear.
  6. The contest continues through October 9, with further attempts expected against the Galaxy S26, Google Pixel 10, and remaining smart home, AI, and printer targets.

Sources