Skip to content
feed: live
0dayNews
threat intel
● Breaking

Pwn2Own Ireland: 32 Zero-Days Fall on Day One

Pwn2Own Ireland 2026 opened with 32 zero-day exploits and $388,500 in payouts. Samsung Galaxy S26 was compromised twice. CVEs pending vendor notification.

Pwn2Own Ireland: 32 Zero-Days Fall on Day One
Image: AI-generated — no human photographer / 0dayNews AI Cover · Generated on-site infrastructure — no external license
airgapMorgan "airgap" Reyes·Published ·1 min read

Day one of Pwn2Own Ireland 2026. Thirty-two zero-day vulnerabilities demonstrated. Researchers collected $388,500.

The Samsung Galaxy S26 was hacked twice.

Pwn2Own runs under Trend Micro’s Zero Day Initiative. Researchers pre-register exploit attempts against specific targets. Each successful attempt requires a live demonstration on a fully patched, unmodified device. ZDI notifies the affected vendor the same day; the standard 90-day disclosure clock starts then. CVE IDs are not assigned during competition.

All 32 vulnerabilities are under embargo pending vendor notification. No patches are available yet for any of them.

The competition is multi-day. More results expected before it closes.

Source: BleepingComputer, October 6, 2026.


Related coverage: Rejetto HFS RCE Under Active Exploitation, ZITADEL Patches Four Auth Bypass Flaws, Two Critical, YesWiki Flaws Let Attackers Spoof Identity, Hijack SMTP

Found this useful? Share it.