Threat reportVulnerabilityTL-2026-3095
Pwn2Own Ireland 2026: 98 Zero-Days Demonstrated Across Mobile, AI, Messaging, Smart Home, Printer and Healthcare Devices
Pwn2Own Ireland 2026 (TL-2026-3095), also tracked as Pwn2Own Ireland 2026, is a high-severity software vulnerability, first published 2026-10-09 and last reviewed 2026-10-10. It has no confirmed attribution, affects Samsung Galaxy S26, maps to 8 MITRE ATT&CK techniques (T1059, T1068, T1078.001), and is covered by 9 detection rules and 21 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 8MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 21Indicators of compromise
Key facts for TL-2026-3095
- Threat ID
- TL-2026-3095
- Also known as
- Pwn2Own Ireland 2026
- Severity
- HIGH
- Status
- MONITORING
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- technology, consumer electronics, health, enterprise it, telecoms
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 21
- Updates
- 2026-10-10 · revalidated 1× · latest source
How Pwn2Own Ireland 2026 works
At Pwn2Own Ireland 2026 (organized by Trend Micro's Zero Day Initiative, 6-8 October 2026), contestants earned $1,262,000 for 98 zero-day vulnerabilities across the Samsung Galaxy S26, Google Pixel 10, AI infrastructure, AI coding applications, smart home devices, printers and wellness devices. Vendors have 90 days to patch before ZDI publishes details; no CVEs, CVSS scores or in-the-wild exploitation were stated in the sources.
Pwn2Own Ireland 2026 was a three-day live hacking contest run by Trend Micro's Zero Day Initiative (ZDI) in Ireland. According to BleepingComputer, contestants demonstrated 98 zero-day vulnerabilities and earned $1,262,000 in total across seven target categories: mobile phones (Samsung Galaxy S26, Google Pixel 10), AI infrastructure, AI coding applications, messaging apps, smart home devices, printers and wellness healthcare devices. ZDI's daily result posts break the total down as Day 1: 32 zero-days and $388,500; Day 2: 45 zero-days and $232,500; Day 3: 21 zero-days and $641,000. Apple's iPhone 17 (maximum $300,000) received no registration attempts. The previous year's event (Pwn2Own Ireland 2025) saw 73 zero-days and $1,024,750 in rewards.
The leaderboard was topped by Ikotas Labs with $361,000 and 42.5 Master of Pwn points, followed by Xint with $240,000 and 27.5 points and Team ZyGoat with $125,000 and 27.5 points. The largest single award was $300,000 (30 points) to Ikotas Labs for chaining multiple issues to compromise the Google Pixel 10 on Day 3. Xint (Tim Becker and Yves Bieri) also compromised the Pixel 10 with a single bug (one collision) for $150,000, and CENSUS Labs/Djini.ai used a two-bug chain (one collision, one zero-day) for $112,500. Several earlier Pixel 10 attempts failed within the time limit.
The Samsung Galaxy S26 was exploited repeatedly (reported as six successful exploits across Days 1-2 plus a further entry on Day 3 by BunkyoWesterns), many with partial collisions where bugs were already known to the vendor or to other contestants. CENSUS Labs demonstrated a confused-deputy flaw (CWE-441) against the S26. AI-related targets included LiteLLM (improper input validation / code injection, $40,000 to Xint's Taisic Yun), OpenAI Codex (argument injection, $40,000 to Ikotas Labs), Oracle Autonomous AI Database (multi-bug chains including use-after-free and type confusion) and Chroma. Other successful targets included Sonos Era 300 (OOB write and format string, $50,000 to @_McCaulay), Philips Hue Bridge Pro (7 zero-day bugs, $40,000 to VinSOC), Home Assistant Green, Garmin Index BPM (OOB read/write), Lexmark CX532adwe (use-after-free and others), Canon imageFORCE 1643F (hard-coded credentials, missing authentication, command injection) and Brother MFC-L8970CDW (single zero-day, $20,000 to FuzzingLabs).
Defensive relevance: the sources do not provide CVE identifiers, CVSS scores, affected version numbers, technical exploit details or evidence of in-the-wild exploitation, and no exploit code has been published. Under ZDI's coordinated disclosure policy vendors have 90 days to ship fixes before details are released, so technical write-ups and CVEs are expected to follow. The HIGH severity is analyst-assigned based on working zero-day exploit chains (including remote code execution style compromises and multi-bug chains) against widely deployed products; it is not sourced from the articles. Defenders should inventory the named products, apply vendor updates as soon as they ship, and watch ZDI advisories for the resulting CVEs.
MITRE ATT&CK techniques used in TL-2026-3095
Execution
T1059 Command and Scripting Interpreter; T1203 Exploitation for Client Execution; T1204 User Execution
Privilege Escalation
T1068 Exploitation for Privilege Escalation; T1404 Exploitation for Privilege Escalation
Initial Access
T1078.001 Valid Accounts: Default Accounts; T1190 Exploit Public-Facing Application; T1664 Exploitation for Initial Access
Affected products and versions in Pwn2Own Ireland 2026
- Samsung — Galaxy S26
Vulnerable versions: Version not disclosed - Google — Pixel 10
Vulnerable versions: Version not disclosed - OpenAI — Codex
Vulnerable versions: Version not disclosed - LiteLLM — LiteLLM
Vulnerable versions: Version not disclosed - Oracle — Autonomous AI Database
Vulnerable versions: Version not disclosed - Chroma — Chroma
Vulnerable versions: Version not disclosed - Sonos — Era 300
Vulnerable versions: Version not disclosed - Signify (Philips) — Hue Bridge Pro
Vulnerable versions: Version not disclosed - Home Assistant — Home Assistant Green
Vulnerable versions: Version not disclosed - Garmin — Index BPM
Vulnerable versions: Version not disclosed
Remediation for Pwn2Own Ireland 2026
Patches
- Vendor patches are pending; vendors have 90 days from disclosure to patch before ZDI publishes details. Apply updates as soon as they are released
Immediate actions
- Inventory deployed Samsung Galaxy S26, Google Pixel 10, Sonos Era 300, Philips Hue Bridge Pro, Home Assistant Green, Garmin Index BPM, Lexmark CX532adwe, Canon imageFORCE 1643F and Brother MFC-L8970CDW devices
- Segment printers, smart home hubs and speakers from corporate and sensitive networks and restrict inbound access from untrusted networks
- Restrict internet exposure of LiteLLM, Chroma and Oracle Autonomous AI Database management and API endpoints
Workarounds
- Disable unneeded network services and remote management on printers and smart home hubs until patches are available
- Change default and hard-coded credentials where the device allows it and require authentication on management interfaces
Longer-term hardening
- Subscribe to ZDI published advisories and vendor security bulletins to map the CVEs released after the 90-day disclosure window
- Enforce least privilege and sandboxing for AI coding agents and AI gateway services (for example OpenAI Codex and LiteLLM)
- Enable automatic firmware and OS updates on mobile, printer and IoT fleets
Weaknesses (CWE) in Pwn2Own Ireland 2026
Timeline of Pwn2Own Ireland 2026
- Ikotas Labs earned $40,000 for an argument-injection exploit against OpenAI Codex; Xint's Taisic Yun earned $40,000 for code injection against LiteLLM.
- Pwn2Own Ireland 2026 Day 1: 32 zero-days demonstrated for $388,500; Samsung Galaxy S26, OpenAI Codex, LiteLLM, Sonos Era 300, Philips Hue Bridge Pro and Oracle Autonomous AI Database fell, while Pixel 10 attempt by White Noise Club failed on time.
- CENSUS Labs demonstrated a confused-deputy (CWE-441) vulnerability against the Samsung Galaxy S26; the Galaxy S26 was exploited six times across Days 1 and 2 per press reporting.
- Day 2: 45 zero-days demonstrated for $232,500, covering Home Assistant Green, Sonos Era 300, Canon imageFORCE 1643F, Lexmark CX532adwe, Chroma, Oracle Autonomous AI Database, Garmin Index BPM and Samsung Galaxy S26.
- Ikotas Labs chained multiple zero-days to compromise the Google Pixel 10, earning the contest's top $300,000 award and 30 Master of Pwn points, and was named Master of Pwn with $361,000 total.
- Day 3: 21 zero-days demonstrated for $641,000 including Pixel 10 compromises by Xint ($150,000, single bug) and CENSUS Labs/Djini.ai ($112,500, two-bug chain).
- BleepingComputer reports final totals of $1,262,000 for 98 zero-days; Xint ($240,000) and Team ZyGoat ($125,000) placed second and third.
- Approximate end of the 90-day vendor patch window (computed from the 2026-10-08 final day) after which ZDI may publicly release technical details.
Update history for TL-2026-3095
- 2026-10-10 — Pwn2Own Ireland 2026 Day 1: Unique 0-Days Demonstrated Against Samsung Galaxy S26, OpenAI Codex, LiteLLM, Oracle Autonomous AI Database, Philips Hue Bridge Pro and Other Devices: What changed No change to severity (HIGH), exploitability (NONE) or status (MONITORING). The newer report is a Day 1-focused view of the same contest and adds detail only. New indicators (7) 5 new entities (VinSOC, Interrupt Labs, Viettel C
Sources cited for Pwn2Own Ireland 2026
- Hackers get $1,262,000 for 98 zero-days at Pwn2Own Ireland
- Pwn2Own Ireland 2026 - Day One Results (ZDI)
- Pwn2Own Ireland 2026 - Day Two Results (ZDI)
- Pwn2Own Ireland 2026 - Day Three Results & Master of Pwn (ZDI)
- 32 Unique 0-Days Exploited in Samsung S26, Pixel 10, OpenAI Codex and Other Devices in Pwn2Own 2026
- Pwn2Own Ireland 2026: 32 Zero-Days, Samsung Galaxy S26 Hacked Twice
- Pwn2Own Ireland 2026: Galaxy S26 Hacked 6 Times, $608K Paid
- Pwn2Own Ireland 2026 Day One: 32 Zero-Days, $388,500 in Payouts
Detection coverage for TL-2026-3095
As of 2026-10-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3095 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.