Thirty-two zero-day vulnerabilities and more than $368,000 in prizes were uncovered on the first day of Pwn2Own Ireland 2026, organizers reported — a haul that underlined both the breadth of modern attack surfaces and the intensity of today’s ethical-research community.
Pwn2Own Ireland 2026 — day one totals and scope
Some of the world’s top ethical hackers arrived in Cork on October 6 for the Zero Day Initiative’s Pwn2Own Ireland, and on day one teams targeted smartphones, smart home devices, printers and AI tools such as OpenAI Codex and LiteLLM. The first day produced 32 zero-day flaws, over $368,000 in prize money and a trove of "Master of Pwn" points that will be tallied at the competition’s close.
Notable teams, techniques and affected products
- @_McCaulay combined an out‑of‑bounds write and a format string bug to exploit the Sonos Era 300.
- Taisic Yun of Xint used an improper input validation bug and code injection to obtain a reverse shell on LiteLLM.
- Vũ Chí Thành and Huỳnh Đức Tin of VinSOC discovered seven zero days during their exploit of the Philips Hue Bridge Pro.
- Thanh Do of Team Confused used a single use‑after‑free exploit against the Lexmark CX532adwe.
- Nam Nguyen, Thanh Vu and Tin Huynh of VinSOC combined five zero days to exploit the Oracle Autonomous AI Database.
- Ikotas Labs, Inc. exploited OpenAI Codex using a single argument injection bug.
- Interrupt Labs used an out‑of‑bounds read and an out‑of‑bounds write to exploit the Garmin Index BPM.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleResponsible disclosure through the Zero Day Initiative (ZDI)
Pwn2Own operates as part of the Zero Day Initiative. The competition’s findings are disclosed responsibly to the relevant vendors, who are given 90 days to issue updates before ZDI publishes the details. That formal window frames the immediate follow-up: identified flaws may prompt urgent remediation cycles from multiple vendors across consumer and enterprise product lines.
AI-enabled tools and trends in vulnerability discovery — Google data and other research
Organizers and observers noted an increasing role for AI in offensive research. According to Google, vulnerability disclosures rose sharply in 2026: from 5,045 in January to 10,477 in July and 10,740 in August. Google also reported that exploited vulnerabilities increased from an average of 10.5 per month in 2025 to 18 per month so far in 2026.
Google further found that AI‑identified vulnerabilities tend to be higher impact: 50% of vulnerabilities it identified as likely AI‑discovered resulted in remote code execution, compared with 26% of other CVEs. By contrast, separate research cited at the event claims that only 1% of AI‑discovered vulnerabilities have been exploited in the wild.
What this means for security teams, vendors, and end users
- Security teams and technologists: the variety of exploited targets — from smart speakers and home hubs to printers, wearables and AI platforms — means defenders must watch both traditional firmware/OS update channels and newer AI toolchains for disclosed fixes.
- Vendors and procurement leaders: the ZDI 90‑day disclosure window will force triage and patching schedules for affected products such as the Sonos Era 300, Philips Hue Bridge Pro, Lexmark CX532adwe, Garmin Index BPM, LiteLLM and Oracle Autonomous AI Database; vendors will need to coordinate updates and customer communications within that timeframe.
- End users and enterprises: devices and services already on home and corporate networks — including smart home hubs and printers — were explicitly targeted on day one, underscoring the practical exposure of connected equipment if timely updates are not applied.
Pwn2Own’s competition continues on October 7 and 8, when organizers will total Master of Pwn points and announce the overall winner. The immediate question left by day one’s results is straightforward and procedural: will vendors meet the 90‑day update obligation for each disclosed flaw, and how quickly will those updates reach end users?




