The second day of Pwn2Own Ireland 2026 was particularly revealing , as cybersecurity researchers managed to identify and exploit a total of 45 unique zero-day vulnerabilities , collecting $232,500 in prize money. The focus was on smartphones, smart home devices, databases and artificial intelligence infrastructure, among others.

The competition, organized by Zero Day Initiative (ZDI) , is one of the most important events in the field of offensive security, as it enables researchers to demonstrate in practice that they can bypass the defenses of modern and fully updated products.
See also: Brocade Fabric OS: Broadcom patches 25 serious vulnerabilities
Pwn2Own Ireland 2026: Three different attacks on the Galaxy S26
The Samsung Galaxy S26 was one of the biggest stars of the second day, as it was hacked three times by independent research teams.
Specifically, successful attacks were presented by Kyeongmin Kim from KAIST Hacking Lab, PetoWorks, and a team of Dimitrios Valsamaras, Ken Gannon, and Tenia Valsamara from CENSUS Labs.
The fact that the same flagship smartphone was repeatedly compromised using different techniques highlights the complexity of modern mobile ecosystems. A smartphone is no longer just a communication device, but a complex system that combines operating system, applications, modem, wireless technologies and cloud services.
From the Sonos Era 300 to AI infrastructures
Also impressive was the demonstration by Jack Dates from RET2 Systems, who managed to present an exploit chain against the Sonos Era 300 in less than a minute.
Meanwhile, HaeJung Yang of Out of Bounds won a $40,000 prize for a successful attack on Dynamoin the AI Infrastructure category. The presence of AI infrastructure in the competition is becoming increasingly important as these platforms are increasingly used for critical business functions.
AI infrastructure security is no longer limited to protecting a single model. It includes servers, databases, APIs, orchestration layers, and data storage systems, creating a much larger attack surface.
See also: Hackers exploit critical Atlassian vulnerability

The smart home is also in the spotlight
Multiple successful attacks were also recorded on Home Assistant Green. Among the researchers who managed to breach it were PetoWorks, Yves Bieri of Xint, Kyeongmin Kim, _McCaulay, as well as Yassine Bengana and Maxence Schmitt of Doyensec.
At the same time, Ikotas Labs presented a particularly complex attack on the Oracle Autonomous AI Database, using a chain of seven zero-day vulnerabilities.
This case demonstrates the importance of exploit chains. An attacker doesn't necessarily need a single critical vulnerability. They can combine several smaller vulnerabilities so that one paves the way for the next and ultimately gain complete control of the target.
How Pwn2Own works
According to Pwn2Own rules , devices and products participating in the competition must be fully updated with the latest firmware and software versions. Researchers are required to demonstrate that they can bypass built-in defenses and execute arbitrary code.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
After successfully demonstrating an unknown vulnerability, ZDI notifies the manufacturer and gives them a 90-day to develop and release a fix. Only after this period can a public disclosure follow.
This process is of particular value to the market because it turns an attack that could be used covertly by criminals into an opportunity for coordinated remediation.
What follows the third day?
Pwn2Own Ireland 2026 continues with new efforts against smart home devices, printers and AI infrastructure, while researchers will also return to the Samsung Galaxy S26 and Google Pixel 10.
See also: SonicWall: Critical vulnerability in SMA1000 devices

It is worth noting that the iPhone 17 was also included in the possible targets, with a maximum reward of $300,000 for remote hacking, but no such attempt was ultimately made.
This year's event comes on the heels of a particularly productive Pwn2Own Ireland 2025, where 73 zero-day vulnerabilities and a total of $1,024,750 in prizes were awarded.
The results of this year's competition are a reminder that even devices with the latest updates can contain unknown critical vulnerabilities. For manufacturers, Pwn2Own acts as a real strength test of their products and, at the same time, as a mechanism for early detection of problems before they fall into the hands of cybercriminals.
source: www.bleepingcomputer.com
