# Pwn2Own Ireland Uncovers 32 Zero-Days Across Diverse Systems

> Security researchers exploited 32 zero-day vulnerabilities in mobile phones, smart home devices, and AI systems on day one of Pwn2Own Ireland 2026.

- Published: 2026-10-06T20:41:01.000Z
- Severity: high
- Category: Vulnerabilities
- Tags: Pwn2own, Zero-Day, OpenAI Codex, Samsung Galaxy S26, Philips Hue Bridge Pro
- Author: Runtime Rebel Intel
- Primary source: https://www.bleepingcomputer.com/news/security/hackers-exploit-32-zero-days-on-first-day-of-pwn2own-ireland/
- Canonical: https://runtimerebel.com/blog/pwn2own-ireland-uncovers-32-zero-days-across-diverse-systems

## Key points

- 32 zero-day vulnerabilities were demonstrated in critical systems, posing future exploitation risks.
- Affected systems include Samsung Galaxy S26, Philips Hue Bridge Pro, Oracle Autonomous AI Database, AI agents, and printers.
- Vendors must promptly develop and deploy patches within the 90-day disclosure window.

The Pwn2Own Ireland 2026 competition has commenced with a significant first day, witnessing security researchers successfully [exploit](/glossary#exploit) 32 [zero-day](/glossary#zero-day) vulnerabilities across a diverse range of devices and platforms. This impressive demonstration on the event's opening day resulted in cumulative earnings of $388,500 for the participating teams. The competition, organized by the Zero Day Initiative (ZDI), aims to identify critical security flaws before malicious actors can leverage them, providing vendors with an opportunity to [patch](/glossary#patch) vulnerabilities proactively.

## Pwn2Own Ireland 2026 Zero-Day Exploits: A Technical Overview

The first day of Pwn2Own Ireland highlighted the susceptibility of popular consumer electronics, smart home ecosystems, and advanced [AI](/glossary#ai) infrastructure. Competitors targeted products across several categories, including mobile phones, printers, smart home devices, messaging apps, and AI infrastructure.

### Mobile Device Breaches

Among the most notable successes was the double compromise of the **Samsung Galaxy S26 zero-day vulnerabilities**. Teams from Interrupt Labs, Ikotas Labs, and Nguyen Thanh Dat of Viettel Cyber Security successfully demonstrated two separate exploit chains against Samsung's flagship mobile device. These findings underscore the continuous security challenges even in state-of-the-art consumer devices. While some of the exploited bugs were already known to the vendor, the successful demonstration in a live environment provides critical validation of their impact. An attempt to exploit the Google Pixel 10 by the White Noise Club team, comprising Mikhail Evdokimov, Polina Smirnova, and Mate Zombor, was unsuccessful within the allotted time.

### Smart Home and AI Infrastructure Compromises

The smart home category saw significant activity, with Vũ Chí Thành and Huỳnh Đức Tin of VinSOC topping the leaderboard for the day. Their team successfully chained seven zero-days to compromise a Philips Hue Bridge Pro smart lighting hub, earning them $40,000. This demonstrates the potential for complex, multi-stage attacks even against seemingly innocuous smart home devices.

VinSOC also targeted critical enterprise and AI systems, earning an additional $40,000 for a five zero-day [exploit chain](/glossary#exploit-chain) against the Oracle Autonomous AI Database. This highlights the growing focus on vulnerabilities within artificial intelligence and machine learning platforms. Further demonstrations included exploits against LiteLLM zero-days. The OpenAI Codex cloud-based AI coding agent was also taken down by an unspecified research team using a single argument-injection bug, emphasizing the potential for common software flaws to impact sophisticated AI tools. Additionally, four distinct vulnerabilities were chained to compromise a Sonos Era 300 smart speaker.

### Printer Vulnerabilities

Multi-function printers also proved to be vulnerable targets. Security researchers successfully hacked both the Lexmark CX532adwe and Canon imageFORCE 1643F devices. Printers, often overlooked in enterprise security strategies, can serve as crucial entry points into corporate networks due to their persistent connectivity and access to sensitive documents.

## Implications for Defenders and Users

The Pwn2Own event serves as a critical mechanism for proactive [vulnerability](/glossary#vulnerability) disclosure. By demonstrating these zero-days in a controlled environment, ZDI facilitates their responsible disclosure to affected vendors. According to [BleepingComputer](https://www.bleepingcomputer.com/news/security/hackers-exploit-32-zero-days-on-first-day-of-pwn2own-ireland/), vendors are given a 90-day window to develop and release security updates before ZDI publicly discloses the technical details of the vulnerabilities. This process helps prevent malicious actors from discovering and exploiting these flaws in the wild before patches are available.

The successful exploitation of multiple zero-days in a variety of widely used products underscores the persistent challenge of software security. Even well-resourced vendors like Samsung, Oracle, and OpenAI are susceptible to sophisticated exploit chains. For organizations and individual users, these findings reiterate the importance of a vigilant security posture. The presence of **securing AI infrastructure against zero-days** is particularly pertinent given the increasing reliance on AI-driven systems.

## Actionable Recommendations: Mitigating Zero-Day Risks

Defenders must remain proactive in light of these revelations. While the specific details of the 32 zero-days are currently undisclosed to allow vendors time to patch, the general categories of affected devices provide immediate areas of focus.

*   **Monitor Vendor Advisories:** IT and security teams should actively monitor official security advisories from Samsung, Philips, Oracle, Lexmark, Canon, OpenAI, and Sonos. Patches addressing these Pwn2Own discoveries are expected within the next 90 days. Prioritize applying these updates immediately upon release to mitigate risks associated with **Samsung Galaxy S26 zero-day vulnerabilities** and other devices.
*   **Implement Defense-in-Depth:** For devices that cannot be immediately patched, or for which patches are pending, implement additional layers of security controls. This includes [network segmentation](/glossary#network-segmentation) for smart home devices, strong access controls for AI platforms, and secure configuration baselines for printers.
*   **Segment AI Infrastructure:** Given the successful attacks against AI components like the Oracle Autonomous AI Database and OpenAI Codex, organizations deploying AI systems should ensure these are adequately isolated from sensitive corporate networks. Implement [least privilege](/glossary#least-privilege) principles and monitor AI infrastructure for anomalous behavior.
*   **Regular Security Audits:** Conduct regular security audits and [penetration testing](/glossary#penetration-testing), particularly for smart home, IoT, and AI deployments that may be overlooked in traditional security assessments. This helps identify and address potential attack vectors before they are exploited.
*   **User Awareness:** Educate users about the importance of promptly installing software and [firmware](/glossary#firmware) updates, especially for mobile devices and smart home technology, as these frequently receive security patches.

**Related:** [SonicWall SMA 1000 Zero-Days: Unauthenticated RCE Explained](/blog/sonicwall-sma-1000-zero-days-unauthenticated-rce-explained), [Pixel 9 Zero-Click RCE: Exploiting Dolby Unified Decoder](/blog/pixel-9-zero-click-rce-exploiting-dolby-unified-decoder)

---

AI-generated analysis from the primary source above; not human-reviewed before publication — verify anything operational against the original (https://runtimerebel.com/editorial). Quote with attribution and a link to the canonical URL: https://runtimerebel.com/blog/pwn2own-ireland-uncovers-32-zero-days-across-diverse-systems
