VYPR
researchPublished Oct 7, 2026· 1 source

Pwn2Own Ireland Hackers Uncover 32 Zero-Day Vulnerabilities on Day One

Ethical hackers at Pwn2Own Ireland 2026 discovered 32 zero-day vulnerabilities across a range of devices and AI tools, winning over $368,000 in prizes on the competition's first day.

The Pwn2Own Ireland 2026 hacking competition, held in Cork, has kicked off with a significant haul of 32 zero-day vulnerabilities discovered on its opening day. Elite ethical hackers targeted a diverse array of products, including smartphones, smart home devices, printers, and artificial intelligence tools such as OpenAI Codex and LiteLLM. The event, which began on October 6, saw participants secure over $368,000 in prize money for their findings.

The competition format pits security researchers against each other to find and demonstrate novel exploits, with the ultimate goal of encouraging vendors to patch critical flaws before they can be weaponized by malicious actors. This year's event has already highlighted successes across multiple targets. For instance, one researcher combined out-of-bounds write and format string bugs to exploit the Sonos Era 300, while another leveraged improper input validation and code injection to achieve a reverse shell on LiteLLM.

Further demonstrations of exploit prowess included a team from VinSOC discovering seven zero-days in the Philips Hue Bridge Pro, and another researcher successfully exploiting the Lexmark CX532adwe with a single use-after-free vulnerability. The Oracle Autonomous AI Database was also targeted, with a VinSOC team combining five zero-days to compromise it. Ikotas Labs, Inc. demonstrated an argument injection bug against OpenAI Codex, and Interrupt Labs showcased out-of-bounds read and write exploits on the Garmin Index BPM.

Hacking competitions like Pwn2Own play a crucial role in the cybersecurity ecosystem. They serve as a vital testing ground, allowing vendors to identify and address vulnerabilities that might otherwise remain hidden. As part of the Zero Day Initiative (ZDI), all findings are responsibly disclosed to the affected vendors, who are given a 90-day window to develop and release patches before the ZDI publicly discloses the details.

The increasing sophistication and prevalence of AI in cybersecurity research is also a notable trend. While AI tools are being used to discover novel bugs, they are also being employed to find exploits for recently published flaws. Google's data indicates a significant rise in vulnerability disclosures, with exploited vulnerabilities also increasing month-over-month.

However, the nature of AI-discovered flaws is also evolving. Google's analysis suggests that vulnerabilities identified by AI are more likely to result in remote code execution (RCE) compared to those found through traditional human research methods. Despite this, separate research indicates that only a small percentage of AI-discovered vulnerabilities have been actively exploited in the wild, suggesting a potential gap between AI's discovery capabilities and real-world threat actor adoption.

Pwn2Own Ireland 2026 continues through October 7 and 8, with the final 'Master of Pwn' title to be awarded at the conclusion of the event. The ongoing discoveries are expected to provide further insights into the security posture of various consumer and enterprise technologies.

Synthesized by Vypr AI