# Pwn2Own Ireland 2026 Day 1: 32 zero-days demonstrated against Samsung Galaxy S26, Philips Hue Bridge Pro, Oracle Autonomous AI Database, LiteLLM, OpenAI Codex, Sonos Era 300, Lexmark and Canon printers, and Garmin Index BPM

> On Day 1 of Pwn2Own Ireland 2026 (Cork, 6 October 2026), researchers demonstrated 32 zero-day vulnerabilities across consumer devices, printers, AI infrastructure and an AI coding agent, earning $388,500 according to BleepingComputer. Exploitation happened in a controlled contest, not in the wild. No CVE IDs or technical details are public, and vendors have 90 days to patch before ZDI discloses.

- **Published:** 2026-10-06T00:00:00Z
- **Last reviewed:** 2026-10-10T14:10:19.481Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2981
- **ID:** TL-2026-2981
- **Severity:** HIGH
- **Category:** VULNERABILITY
- **Status:** MONITORING
- **Detections:** 9 · **IOCs:** 16 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Pwn2Own Ireland 2026, organised by Trend Micro's Zero Day Initiative (ZDI), runs 6-9 October 2026 in Cork, Ireland. The rules define seven target categories: Mobile Phones, Smart Home, Wellness (new this year), Printers, Messaging (WhatsApp), AI Infrastructure, and AI Coding Agents. Contestants attack fully patched targets from a laptop on the contest network, or via the default browser or NFC/Wi-Fi/Bluetooth for phones.

BleepingComputer (Sergiu Gatlan, 2026-10-06) reports that 32 zero-days were exploited on Day 1 for $388,500 in total. The reported results are: Samsung Galaxy S26 hacked by Interrupt Labs, Ikotas Labs and Nguyen Thanh Dat (Viettel Cyber Security), with some bugs 'already known to the vendor'; a seven-zero-day chain against the Philips Hue Bridge Pro ($40,000) and a five-zero-day chain against Oracle Autonomous AI Database ($40,000) by VinSOC researchers, $80,000 combined for Vu Chi Thanh and Huynh Duc Tin per BleepingComputer; LiteLLM zero-days; Lexmark CX532adwe and Canon imageFORCE 1643F multifunction printers; a single argument-injection bug in OpenAI Codex; four vulnerabilities in the Sonos Era 300; and an unsuccessful attempt on the Google Pixel 10 by White Noise Club.

The ZDI Day 1 results post lists per-entry detail for 21 entries. The BleepingComputer 'four vulnerabilities' on the Sonos Era 300 matches the sum of two entries, @_McCaulay (2 bugs: out-of-bounds write and format string, $50,000) and linhlhq and Son Dinh of VinSOC (2 bugs, 1 known, $17,500). Other confirmed entries: Taisic Yun (Xint) LiteLLM, 2 bugs (input validation and code injection, $40,000); Out of Bounds LiteLLM, 4 bugs with 2 known ($15,000); Thanh Do (Team Confused) Lexmark use-after-free ($20,000); Sina Kheirkhah (Summoning Team) Lexmark single bug ($10,000); Interrupt Labs Garmin Index BPM, out-of-bounds read and write ($20,000); Ikotas Labs OpenAI Codex argument injection ($40,000); Galaxy S26 entries by Nguyen Thanh Dat (4 bugs, 3 known, $31,250), Interrupt Labs (4 bugs, 3 known, $15,750) and Ikotas Labs (4 bugs, 1 known, $11,000); Hue Bridge Pro collisions by Out of Bounds (5 bugs, 4 known, $12,000) and Xint's Joohyun Park (5 bugs, 4 known, $6,000). Failed or non-working entries: Brother MFC-L8970CDW (Ikotas Labs), Lexmark CX532adwe (Team T-X Lab), Garmin Index BPM (Summoning Team), Google Pixel 10 (White Noise Club) and Chroma (VinSOC). The ZDI results page as fetched did not include the Canon imageFORCE 1643F entry or the end-of-day totals; the 32-zero-day and $388,500 figures are from BleepingComputer only. The listed ZDI rows sum to $368,500, so the remaining $20,000 would match one Canon payout at the listed $20,000 target price, but this is an inference, not a stated fact.

No CVE identifiers, CVSS scores, affected firmware versions or exploit details have been published. ZDI discloses vulnerabilities to vendors and, per BleepingComputer, vendors have 90 days to patch before public disclosure. The competition continues 7-9 October with further entries against the Pixel 10, Galaxy S26, Home Assistant Green, Oracle, Chroma, Dynamo, other AI targets and printers. The Day 1 total compares with 2025's event, which ended with 73 zero-days and $1,024,750. Defenders should treat this as a watch item: inventory the named products and prioritise the vendor patches expected after the disclosure window, in particular internet-exposed LiteLLM proxies, Oracle AI Database deployments and developer workstations running Codex.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1203 Exploitation for Client Execution
- T1059 Command and Scripting Interpreter
- T1587.004 Develop Capabilities
- T1068 Exploitation for Privilege Escalation
- T1210 Exploitation of Remote Services

## Sources

- [Hackers exploit 32 zero-days on first day of Pwn2Own Ireland](https://www.bleepingcomputer.com/news/security/hackers-exploit-32-zero-days-on-first-day-of-pwn2own-ireland/)
- [Pwn2Own Ireland 2026 - Day One Results (ZDI)](https://www.thezdi.com/blog/2026/10/6/pwn2own-ireland-2026-day-one-results)
- [Pwn2Own Ireland 2026 - The Full Schedule (ZDI)](https://www.thezdi.com/blog/2026/10/5/pwn2own-ireland-2026-the-full-schedule)
- [Pwn2Own Ireland 2026 Rules and Targets](https://www.zerodayinitiative.com/Pwn2OwnIreland2026Rules.html)
- [Pwn2Own Ireland 2026 - New Targets and Categories (ZDI)](https://www.thezdi.com/blog/2026/7/21/pwn2own-ireland-2026-new-targets-and-categories)
- [Pwn2Own Ireland 2025 - Day One Results (ZDI)](https://www.thezdi.com/blog/2025/10/21/pwn2own-ireland-2025-day-one-results)
- [Pwn2Own Ireland 2025 wraps with over $1 million awarded for 73 zero-days (CyberInsider)](https://cyberinsider.com/pwn2own-ireland-2025-wraps-with-over-1-million-awarded-for-73-zero-days/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2981
