Pwn2Own Hackers Find 32 Zero-Day Vulnerabilities on Day One

Written by

Some of the world’s top ethical hackers descended on the Irish city of Cork in an event that began on October 6, where they have already discovered dozens of zero-day flaws in the latest Pwn2Own Ireland.

The hacking competition pits teams against each other in a contest to see who can unearth the most novel vulnerabilities.

On the first day of the Zero Day Initiative’s Pwn2Own Ireland 2026, teams targeted smartphones, smart home devices, printers, and AI tools like OpenAI Codex and LiteLLM.

Their total haul was 32 zero-day vulnerabilities and over $368,000 in prize money, as well as a trove of “Master of Pwn” points which will be totted up at the end of the competition.

Read more on Pwn2Own: Security Researchers Find 47 Zero-Days at Pwn2Own Berlin.

Day one saw several successes, including:

  • @_McCaulay combined an out-of-bounds write and a format string(!) bug to exploit the Sonos Era 300
  • Taisic Yun of Xint used an improper input validation bug and code injection to get a reverse shell on LiteLLM
  • Vũ Chí Thành and Huỳnh Đức Tin of VinSOC found seven zero days during their exploit of Philips Hue Bridge Pro
  • Thanh Do of Team Confused used a single use-after-free exploit on the Lexmark CX532adwe 
  • Nam Nguyen, Thanh Vu, and Tin Huynh of VinSOC combined five zero days to exploit the Oracle Autonomous AI Database
  • Ikotas Labs, Inc. used a single argument injection bug to exploit OpenAI Codex
  • Interrupt Labs used an OOB read and an OOB write to exploit the Garmin Index BPM

Ethical Hacking to the Fore

Hacking competitions like this are arguably more important than ever as vendors struggle to find vulnerabilities in their products before their adversaries do.

As a part of the Zero Day Initiative (ZDI), Pwn2Own findings are responsibly disclosed to the relevant vendors, who then have 90 days to release updates before the ZDI publishes them.

AI-enabled tools are increasingly being used in an offensive capacity to research exploits, either for novel bugs or recently published flaws.

According to Google, vulnerability disclosures doubled from 5045 in January 2026 to 10,477 in July, reaching 10,740 in August 2026. Exploited vulnerabilities rose from an average of 10.5 a month in 2025 to 18 a month so far in 2026.

AI discovery also skews to higher impact flaws: 50% of vulnerabilities Google identified as likely AI-discovered resulted in remote code execution, against 26% of other CVEs.

However, separate research claims that just 1% of AI-discovered vulnerabilities have been exploited in the wild.

Pwn2Own continues on October 7 and 8, when the Master of Pwn will be announced.

What’s Hot on Infosecurity Magazine?