ON 7 October 2026, Pwn2Own Ireland 2026, run by the Zero Day Initiative (ZDI), reported 32 zero-day vulnerabilities uncovered on day one of the event in Cork. The competition targets a range of devices and software, including smartphones, smart home gear, printers and AI tools such as OpenAI Codex and LiteLLM, with more than $368,000 in prize money and Master of Pwn points awarded so far. Findings are disclosed responsibly to vendors, who have 90 days to publish updates before the ZDI releases its full results.
The day’s exploits span several notable disclosures: an out-of-bounds write combined with a format string bug exploited on the Sonos Era 300; Taisic Yun of Xint achieving a reverse shell on LiteLLM via improper input validation and code injection; seven zero-days discovered by Vũ Chí Thành and Huỳnh Đức Tin of VinSOC during an attack on the Philips Hue Bridge Pro; a single
use-after-free exploit used by Thanh Do of Team Confused against the Lexmark CX532adwe; five zero days exploited in the Oracle Autonomous AI Database by Nam Nguyen, Thanh Vu and Tin Huynh of VinSOC; Ikotas Labs, Inc. leveraging a single argument injection to target OpenAI Codex; and Interrupt Labs using an out-of-bounds read and write against the Garmin Index BPM.
The article notes growing use of AI-enabled tooling in vulnerability research and contrasts exploitation rates with broader disclosure trends.