HomeSecurityPwn2Own 2026: 32 zero-day vulnerabilities on the first day

Pwn2Own 2026: 32 zero-day vulnerabilities on day one

The first day of the Pwn2Own 2026 competition saw successful attacks on mobile phones, smart home devices, printers and artificial intelligence tools. BleepingComputer estimated that 32 zero-day vulnerabilities were exploited and reported a total prize pool of $388,500, while the official results also recorded several cases of known bugs.

Pwn2Own 2026 smart home devices

The competition is being held in Cork, Ireland from October 6-9, with entries in seven categories. The Zero Day Initiative (ZDI) require researchers to demonstrate a specific breach of the target, such as code execution or access to sensitive data.

The demonstrations will continue over the next few days. For the second day, organizers have planned new attempts against Samsung’s Galaxy S26 and Google’s Pixel 10, along with tests on printers, smart home devices and artificial intelligence infrastructure, according to the competition program report.

Pwn2Own 2026 results and known vulnerabilities

The ZDI, the competition organizer, recorded 21 attempts on the first day. In its official report, it distinguishes between successes and “clash” of vulnerabilities: in some exploit chains, some of the bugs were already known to the manufacturer or had been made public. Therefore, the number of successful demonstrations does not automatically equate to the same number of unknown weaknesses.

Among the strongest performances was that of Vũ Chí Thành and Huỳnh Đức Tin from the VinSOC team. They exploited seven zero-day vulnerabilities to compromise the Philips Hue Bridge Pro smart lighting bridge, earning $40,000. The official report also notes that the same team successfully attacked the Oracle Autonomous AI Database.

The second VinSOC demonstration at Oracle relied on a chain of five bugs and yielded an additional $40,000, according to ZDI results. Separate entries tested attacks on the Samsung Galaxy S26, the Sonos Era 300 speaker, printers, and Philips Hue devices. In several of them, however, the researchers also used bugs that were already known.

In AI systems, the Xint team successfully attacked LiteLLM by combining incorrect input validation with code injection. ZDI also confirmed a successful attack on OpenAI Codex via an argument injection error. The demonstrations show that attack surfaces are no longer limited to operating systems and hardware, but also include AI development tools.

See also: Pwn2Own Ireland 2025 – Day 1: 34 zero-day exploits and $522,500 in prizes

Artificial intelligence infrastructure and vulnerabilities

From mobile phones to smart home devices

The range of objectives reflects the variety of devices connected to networks today. Categories include mobile phones, smart home devices, healthcare products, printers, messaging applications, artificial intelligence infrastructures and programming assistants. The event will feature demonstrations in a specific and controlled environment.

The Samsung Galaxy S26 was cracked in successive attempts, with some chains containing bugs that the manufacturer already knew about. In contrast, the White Noise Club team's attempt against the Google Pixel 10 was not completed in the time available. A failed demonstration in a competition is not in itself a certification of the device's security.

These figures need to be read carefully: the competition tests specific versions and configurations, not every device that is released. BleepingComputer reports that after the demonstration, manufacturers are notified through ZDI's coordinated disclosure process and have up to 90 days to make corrections before the technical details are publicly released.

Mobile and smart devices

What the findings mean for users

The successes at Pwn2Own 2026 do not mean that all vulnerabilities are already known or exploited online. Instead, many demonstrations are conducted under controlled conditions and follow a responsible disclosure process, allowing vendors to prepare updates before detailed technical information is released.

Users and organizations should install updates as soon as they are released by manufacturers and monitor official announcements for the products they use. For enterprise AI systems, smart home devices, and network equipment, regular inventory and timely patching limit the exposure window.

See also: Pwn2Own Ireland 2025: $1,024,750 in prizes for 73 zero-days

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The SecNews technical team notes that competitions of this type offer useful insight into new risk categories, without themselves documenting actual attacks against users. As Pwn2Own 2026 continues through October 9, future ZDI announcements will indicate whether new successes and findings will be added.

See also: Pwn2Own Ireland 2025 – Day 2: 56 zero-day exploits & $792,750 in prizes

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS