# Pwn2Own Ireland 2026: 98 Zero-Days Demonstrated Across Mobile, AI, Messaging, Smart Home, Printer and Healthcare Devices

> At Pwn2Own Ireland 2026 (organized by Trend Micro's Zero Day Initiative, 6-8 October 2026), contestants earned $1,262,000 for 98 zero-day vulnerabilities across the Samsung Galaxy S26, Google Pixel 10, AI infrastructure, AI coding applications, smart home devices, printers and wellness devices. Vendors have 90 days to patch before ZDI publishes details; no CVEs, CVSS scores or in-the-wild exploitation were stated in the sources.

- **Published:** 2026-10-09T00:00:00Z
- **Last reviewed:** 2026-10-10T12:52:17.256Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3095
- **ID:** TL-2026-3095
- **Severity:** HIGH
- **Category:** VULNERABILITY
- **Status:** MONITORING
- **Detections:** 9 · **IOCs:** 21 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Pwn2Own Ireland 2026 was a three-day live hacking contest run by Trend Micro's Zero Day Initiative (ZDI) in Ireland. According to BleepingComputer, contestants demonstrated 98 zero-day vulnerabilities and earned $1,262,000 in total across seven target categories: mobile phones (Samsung Galaxy S26, Google Pixel 10), AI infrastructure, AI coding applications, messaging apps, smart home devices, printers and wellness healthcare devices. ZDI's daily result posts break the total down as Day 1: 32 zero-days and $388,500; Day 2: 45 zero-days and $232,500; Day 3: 21 zero-days and $641,000. Apple's iPhone 17 (maximum $300,000) received no registration attempts. The previous year's event (Pwn2Own Ireland 2025) saw 73 zero-days and $1,024,750 in rewards.

The leaderboard was topped by Ikotas Labs with $361,000 and 42.5 Master of Pwn points, followed by Xint with $240,000 and 27.5 points and Team ZyGoat with $125,000 and 27.5 points. The largest single award was $300,000 (30 points) to Ikotas Labs for chaining multiple issues to compromise the Google Pixel 10 on Day 3. Xint (Tim Becker and Yves Bieri) also compromised the Pixel 10 with a single bug (one collision) for $150,000, and CENSUS Labs/Djini.ai used a two-bug chain (one collision, one zero-day) for $112,500. Several earlier Pixel 10 attempts failed within the time limit.

The Samsung Galaxy S26 was exploited repeatedly (reported as six successful exploits across Days 1-2 plus a further entry on Day 3 by BunkyoWesterns), many with partial collisions where bugs were already known to the vendor or to other contestants. CENSUS Labs demonstrated a confused-deputy flaw (CWE-441) against the S26. AI-related targets included LiteLLM (improper input validation / code injection, $40,000 to Xint's Taisic Yun), OpenAI Codex (argument injection, $40,000 to Ikotas Labs), Oracle Autonomous AI Database (multi-bug chains including use-after-free and type confusion) and Chroma. Other successful targets included Sonos Era 300 (OOB write and format string, $50,000 to @_McCaulay), Philips Hue Bridge Pro (7 zero-day bugs, $40,000 to VinSOC), Home Assistant Green, Garmin Index BPM (OOB read/write), Lexmark CX532adwe (use-after-free and others), Canon imageFORCE 1643F (hard-coded credentials, missing authentication, command injection) and Brother MFC-L8970CDW (single zero-day, $20,000 to FuzzingLabs).

Defensive relevance: the sources do not provide CVE identifiers, CVSS scores, affected version numbers, technical exploit details or evidence of in-the-wild exploitation, and no exploit code has been published. Under ZDI's coordinated disclosure policy vendors have 90 days to ship fixes before details are released, so technical write-ups and CVEs are expected to follow. The HIGH severity is analyst-assigned based on working zero-day exploit chains (including remote code execution style compromises and multi-bug chains) against widely deployed products; it is not sourced from the articles. Defenders should inventory the named products, apply vendor updates as soon as they ship, and watch ZDI advisories for the resulting CVEs.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1078.001 Valid Accounts: Default Accounts
- T1059 Command and Scripting Interpreter
- T1203 Exploitation for Client Execution
- T1204 User Execution
- T1068 Exploitation for Privilege Escalation
- T1664 Exploitation for Initial Access
- T1404 Exploitation for Privilege Escalation

## Sources

- [Hackers get $1,262,000 for 98 zero-days at Pwn2Own Ireland](https://www.bleepingcomputer.com/news/security/hackers-earn-1262000-for-98-zero-days-at-pwn2own-ireland/)
- [Pwn2Own Ireland 2026 - Day One Results (ZDI)](https://www.zerodayinitiative.com/blog/2026/10/6/pwn2own-ireland-2026-day-one-results)
- [Pwn2Own Ireland 2026 - Day Two Results (ZDI)](https://www.zerodayinitiative.com/blog/2026/10/7/pwn2own-ireland-2026-day-two-results)
- [Pwn2Own Ireland 2026 - Day Three Results & Master of Pwn (ZDI)](https://www.zerodayinitiative.com/blog/2026/10/8/pwn2own-ireland-2026-day-three-results-amp-master-of-pwn)
- [32 Unique 0-Days Exploited in Samsung S26, Pixel 10, OpenAI Codex and Other Devices in Pwn2Own 2026](https://cybersecuritynews.com/32-0-days-pwn2own-2026/)
- [Pwn2Own Ireland 2026: 32 Zero-Days, Samsung Galaxy S26 Hacked Twice](https://securityarsenal.com/blog/pwn2own-ireland-2026-32-zero-days-samsung-galaxy-s26-hacked-twice-what-defenders-must-do-now)
- [Pwn2Own Ireland 2026: Galaxy S26 Hacked 6 Times, $608K Paid](https://tech-insider.org/pwn2own-ireland-2026-galaxy-s26-six-times/)
- [Pwn2Own Ireland 2026 Day One: 32 Zero-Days, $388,500 in Payouts](https://dailysecurityreview.com/cyber-security/pwn2own-ireland-2026-day-one-32-zero-days-388500-in-payouts/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3095
