Researchers earned $388,500 for exploiting 32 reported unique zero-day vulnerabilities on the opening day of Pwn2Own Ireland 2026. Successful demonstrations targeted the Samsung Galaxy S26, OpenAI Codex, LiteLLM, Oracle Autonomous AI Database, smart home devices and printers. VinSOC led the leaderboard with $80,000 earned through exploit chains against the Philips Hue Bridge Pro and Oracle Autonomous AI Database. Other results included an argument-injection vulnerability in Codex and a four-vulnerability chain compromising the Sonos Era 300. Attempts against Google Pixel 10 and Chroma failed within the contest time limit.
Some successful exploit chains incorporated flaws already known to vendors, resulting in reduced payouts. These were controlled contest demonstrations, not evidence of attacks against real users. Organizer Zero Day Initiative gives vendors 90 days to release security updates before public disclosure; full exploit details, affected versions and a CVE identifier for the Codex flaw were not published. Organizations using the demonstrated products should monitor vendor advisories and prioritize applicable updates as they become available.

Track how attackers are adapting to this technology.
22 events from the most recent confirmed update back to the earliest known activity.
Researchers earned $232,500 for exploiting 45 unique zero-days on Pwn2Own Ireland's second day, with Galaxy S26 successes by Kyeongmin Kim, PetoWorks, and a team comprising Dimitrios Valsamaras, Ken Gannon, and Tenia Valsamara. Other new demonstrations included RET2 Systems' Sonos Era 300 exploit, Out of Bounds' $40,000 Dynamo hack, Ikotas Labs' seven-zero-day Oracle Autonomous AI Database chain, and additional Home Assistant Green compromises.
Yves Bieri of Xint successfully demonstrated an exploit against Home Assistant Green during Pwn2Own Ireland 2026's second day, earning $30,000 and three Master of Pwn points. The reference did not disclose vulnerability classes or exploit-chain details.
Researchers reportedly exploited 32 unique zero-day vulnerabilities and earned $388,500 during the opening day of Pwn2Own Ireland 2026. VinSOC researchers Vũ Chí Thành and Huỳnh Đức Tin topped the day-one leaderboard with $80,000 in awards.
VinSOC exploited Sonos Era 300 using two vulnerabilities for $17,500; Out of Bounds and Xint separately exploited Philips Hue Bridge Pro using five vulnerabilities each, earning $12,000 and $6,000 respectively. Ikotas Labs' Brother MFC-L8970CDW attempt, Team T-X Lab's Lexmark CX532adwe attempt, and Summoning Team researcher Aaron Christophel's Garmin Index BPM attempt all exceeded the allotted time without success.
Interrupt Labs combined an out-of-bounds read with an out-of-bounds write against the Garmin Index BPM wellness device, earning $20,000.
Researchers successfully hacked the Canon imageFORCE 1643F multifunction printer during the opening day of Pwn2Own Ireland 2026.
Sina Kheirkhah of Summoning Team successfully demonstrated a separate exploit against the Lexmark CX532adwe printer.
Thanh Do of Team Confused successfully demonstrated an attack against the Lexmark CX532adwe multifunction printer.
McCaulay Hudson successfully exploited the Sonos Era 300 smart speaker, earning $50,000. The reported exploit included an out-of-bounds write and a format string flaw.
Vũ Chí Thành and Huỳnh Đức Tin of VinSOC exploited the Philips Hue Bridge Pro smart lighting hub using seven zero-day vulnerabilities. The demonstration earned $40,000.
VinSOC's separate attempt against Chroma did not succeed before the contest time limit expired.
VinSOC researchers chained five vulnerabilities to successfully exploit Oracle Autonomous AI Database, earning $40,000.
Out of Bounds exploited LiteLLM with a four-vulnerability chain that included two previously known flaws. The team received $15,000.
Taisic Yun of Xint combined improper input validation with code injection to obtain a reverse shell on LiteLLM, earning $40,000.
Ikotas Labs compromised the OpenAI Codex cloud-based coding agent through a single argument-injection vulnerability, earning $40,000. ZDI's day-one report did not disclose full exploit steps, affected versions, or a CVE identifier.
Mikhail Evdokimov, Polina Smirnova, and Mate Zombor of White Noise Club could not complete their Google Pixel 10 exploit within the contest's allotted time.
Ikotas Labs demonstrated a four-bug chain containing three new vulnerabilities and one flaw Samsung already knew about but had not patched. The team earned $11,000.
Interrupt Labs successfully exploited the Samsung Galaxy S26 using one zero-day and three previously reported vulnerabilities. The team received a reduced award of $15,750 because of the overlapping discoveries.
Nguyen Thanh Dat of Viettel Cyber Security demonstrated a four-bug exploit chain combining one new vulnerability with three vendor-known flaws, earning $31,250.
Pwn2Own Ireland 2026 concluded after three days with researchers earning $1,262,000 for demonstrating 98 zero-day vulnerabilities; the third day contributed $641,000 and 21 zero-days. Ikotas Labs finished first with $361,000 and 42.5 Master of Pwn points, followed by Xint with $240,000 and Team ZyGoat with $125,000.
FuzzingLabs exploited the Brother MFC-L8970CDW with a single zero-day, while Team DDOS compromised Home Assistant Green, Platform Security exploited Oracle Autonomous AI Database, Summoning Team compromised the Canon imageFORCE 1643F, and @_McCaulay exploited Philips Hue Bridge Pro. Ikotas Labs was declared Master of Pwn after its $300,000 Google Pixel 10 exploit moved it to the top of the leaderboard.
Ikotas Labs earned $300,000 for chaining multiple bugs to remotely compromise a Google Pixel 10. Tim Becker and Yves Bieri received $150,000, while Dimitrios Valsamaras and Ken Gannon earned $112,500 for separate Pixel exploits, with both awards reduced because their chains included previously known vulnerabilities.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
14 references tracked. Mallory keeps watching after this page renders.
fuzzinglabs.com
Open sourcethehackernews.com
Open sourcesecurityweek.com
Open sourcebleepingcomputer.com
Open sourcebleepingcomputer.com
Open sourcezerodayinitiative.com
Open sourcetrendmicro.com
Open sourcezerodayinitiative.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.