Pwn2Own Ireland Closes: $1.26M for 98 Zero-Days
Pwn2Own Ireland 2026 wrapped with 98 unique zero-day vulnerabilities exploited and $1,262,000 in prizes paid out to competing security researchers.

Pwn2Own Ireland 2026 is over. Competing researchers exploited 98 unique zero-day vulnerabilities and walked away with $1,262,000 in prize money, per BleepingComputer.
The final tally builds on a contest that started strong. Day one produced 32 zero-days. Day two added 45 more and $232,500. The Samsung Galaxy S26 was hit three separate times across the competition.
There is a version of this story that frames 98 zero-days as alarming. It is not wrong, exactly. But it is also not new. Pwn2Own has run for nearly two decades, and the pattern holds: researchers find what vendors missed, vendors patch it, everyone declares the system works. The contest outcome does not tell us whether those 98 flaws were novel in class or iterative variations on attack surfaces the industry has known about for years. That breakdown matters more than the dollar figure, and it tends to come later in researcher writeups.
What the numbers do confirm: the attack surface of modern devices remains wide. Browser exploitation, kernel escapes, and hardware-adjacent bugs are not going away because they are structurally hard problems, not neglected ones. Prizes this size attract serious talent, which means the research quality is high and the findings are real. That is the part worth noting.
Under the rules, vendors receive the vulnerability details at the time of exploitation. Patches follow; timelines vary by vendor. Until those patches ship and deploy, the flaws demonstrated here remain live. The Samsung, browser, and OS-level bugs shown at this year’s contest will be detailed in researcher writeups in the coming weeks. Watch those for the technical specifics vendors will be racing to close.
Found this useful? Share it.


