Pwn2Own Ireland opens with 32 zero-day exploits and $388,500 in awards
Day one showed vendors how fast fresh flaws can be turned into working attacks when researchers line up against real products.
Pwn2Own Ireland 2026 opened with researchers chaining 32 zero-days and collecting $388,500, showing how quickly vendors may need to respond when public exploit competitions surface fresh flaws. The Samsung Galaxy S26 was the main target on day one, with Interrupt Labs, Ikotas Labs, and Nguyen Thanh Dat of Viettel Cyber Security successfully demonstrating attacks against it, though some of the bugs in those runs were already known to the vendor. Other day-one wins included zero-days against LiteLLM, the Lexmark CX532adwe and Canon imageFORCE 1643F printers, the OpenAI Codex cloud AI coding agent via argument injection, and four vulnerabilities used again against a Sonos Era 300. The Google Pixel 10 was also targeted, but White Noise Club’s Mikhail Evdokimov, Polina Smirnova, and Mate Zombor did not complete their exploit in time.
Why it matters
The results put several widely used devices and services on the spot at once, from Samsung’s Galaxy S26 to the OpenAI Codex cloud agent and printers from Lexmark and Canon. For the vendors involved, the value of the event is not only the payouts but the proof that multiple bug chains can land in public on the same day, while one Pixel 10 attempt still failed to finish in time.
Keep or strike?
Does this story matter, or is it hype? Mark it before you see what everyone else did.
Sources
- BleepingComputer