Pwn2Own Ireland Day 2: 45 More Zero-Days, $232K
Day two at Pwn2Own Ireland 2026 added 45 zero-day vulnerabilities and $232,500 in prizes. Samsung Galaxy S26 fell three more times. Vendors have 90 days to patch.

The second day of Pwn2Own Ireland 2026 closed with 45 unique zero-day vulnerabilities demonstrated and $232,500 in prizes paid out, according to Trend Micro’s Zero Day Initiative. Combined with day one’s 32 zero-days and $388,500 in awards, the event has now recorded 77 unique vulnerabilities and over $621,000 in researcher payouts across two days.
Samsung Galaxy S26 was compromised three more times on Tuesday, bringing its total to five successful exploits since the contest opened. That’s the most of any single device at this year’s event. Specific CVE IDs are pending: under ZDI’s standard disclosure rules, vendors receive 90 days to ship patches before technical details go public. Until Samsung releases fixes, treat Galaxy S26 as carrying unpatched zero-day exposure in the exploited components.
What actually matters here
Pwn2Own exploits don’t turn into public attacks overnight. The 90-day disclosure clock means researchers, vendors, and defenders all know a patch is coming before details get out. That’s the model working as intended.
The Samsung focus matters more than the raw count. Five successful exploits against one handset in two days points to concentrated researcher interest, which usually means the attack surface is larger than a single patch will close. Watch Samsung’s monthly security bulletins closely for the next three to four months, specifically for Galaxy S26 firmware updates. Android October’s 25-flaw patch cycle already shipped this week; Samsung’s Pwn2Own fixes will follow on their own schedule.
For enterprise security teams: if your organization issues Galaxy S26 devices, document the exposure window now. When Samsung advisories reference these Pwn2Own-origin CVEs, you’ll want rapid deployment rather than a standard patch cycle.
Still running
Pwn2Own Ireland 2026 runs through Thursday. Smart home devices, automotive software, and additional smartphones remain on the target list. ZDI will publish a full summary with CVE assignments once vendor notification windows close.
Found this useful? Share it.


