Pwn2Own Ireland 2026 closed in Cork on 8 October with researchers paid $1,262,000 for 98 previously unknown vulnerabilities in phones, printers, smart home hubs and AI infrastructure. For UK organisations, the more useful takeaway is the patch wave that will follow over the next 90 days and what it says about the kit sitting on their own networks.
What happened
The Zero Day Initiative (ZDI) ran its third Pwn2Own contest in Ireland from 6 to 8 October, with the final results and the Master of Pwn standings published on 8 October. Across the three days, 29 teams made 61 completed attempts against targets in seven categories: mobile phones, messaging, smart home devices, printers, wellness devices, AI infrastructure and AI coding agents.
The running totals tell the story. According to BleepingComputer, the opening day produced 32 zero-days worth $388,500, the second day 45 worth $232,500, and the closing day 21 worth $641,000. That compares with roughly $1.02 million for 73 zero-days at the 2025 edition, so both the bug count and the prize pot rose year on year.
Ikotas Labs took the Master of Pwn title with $361,000 and 42.5 points, overtaking Xint late on the last day. Its decisive entry was a chained exploit against the Google Pixel 10 that earned $300,000 on its own. Xint finished second on $240,000, with Team ZyGoat third on $125,000. Nobody registered an attempt against Apple’s iPhone 17.
The technical picture
The Pixel 10 was the headline target and fell three times on the final day. Xint landed a remote compromise using a single bug, Ikotas Labs chained several issues, and a team combining Mobile Hacking Lab’s Djini.ai tooling with CENSUS Labs researchers paired a fresh zero-day with a known flaw for $112,500. Samsung’s Galaxy S26 was also compromised repeatedly across the week, including a final-day remote entry from BunkyoWesterns.
Much of the action, though, came from less glamorous categories. Home Assistant Green was the most attempted device on day two, and Team MAMMOTH closed the event with a six zero-day chain against it. The Philips Hue Bridge Pro, Sonos Era 300 and Garmin Index BPM wellness device were all exploited. In the printer category, a lone zero-day in a Brother MFC-L8970CDW won FuzzingLabs $20,000, while Canon and Lexmark devices also fell; Interrupt Labs marked its Lexmark success by running DOOM on the printer.
ZDI’s own day two notes describe one Canon imageFORCE chain as combining hard-coded credentials, a missing authentication check on a critical function and command injection. That is a depressingly familiar trio for anyone who tests embedded devices. On the AI side, Oracle’s Autonomous AI Database was breached by several teams, Dynamo and LiteLLM were exploited, and OpenAI’s Codex coding agent was taken down with a single bug on day one.
A recurring word in the results was “collision”. In Pwn2Own terms, that means an exploit worked but used a vulnerability that ZDI or the vendor already knew about, which lowers the payout. Many final-day chains, including the winning Pixel entry, contained collisions. Successful entrants hand their exploit details to ZDI, which passes them to vendors under a 90-day deadline before public disclosure.

Why it matters for UK organisations
None of these targets are exotic. Brother, Canon and Lexmark multifunction printers sit in offices, schools and surgeries across the UK. Smart home hubs and speakers increasingly turn up in meeting rooms and small businesses, and the Pixel and Galaxy ranges are common corporate handsets. Every one of the 98 bugs now sits in a vendor queue, and the fixes will arrive as firmware and app updates over the coming weeks.
There is also a regulatory angle. Since 29 April 2024, the UK product security regime under the Product Security and Telecommunications Infrastructure Act 2022 has required manufacturers of consumer connectable products to publish a way to report vulnerabilities, set out timescales for acknowledging reports, and state a minimum security update period. Several of the device classes hacked in Cork fall squarely into that territory, so buyers can reasonably expect clear advisories and update commitments from vendors selling here.
The contest also lands while the UK is still waiting to see how the Computer Misuse Act 1990 will be rewritten. The government signalled the reform in May, but has not yet published draft legislation, and campaigners such as CyberUp are pressing for what they call a “clear, workable statutory defence” for good-faith research. Pwn2Own shows what structured, authorised research can deliver when the rules are clear.
Expert view
Pwn2Own is sometimes dismissed as a showcase, but I think it is one of the most honest signals in the industry. A cash prize only pays out for a working exploit demonstrated live, not a theoretical finding in a slide deck, and that discipline is exactly what bug bounty programmes try to replicate.
The collision count is the detail I would pay most attention to. When several teams independently arrive at the same flaw, that flaw is not hard to find. If professional researchers are converging on it, so can a capable criminal group, and the vendor’s existing fix pipeline becomes the real line of defence. In my experience, embedded devices such as printers and building controllers are where organisations are slowest to apply firmware updates, because nobody clearly owns them.
The AI infrastructure results deserve a mention too. Model gateways, vector databases and coding agents are being deployed quickly, often by development teams outside the normal change process. When we test environments like these, the assumption that a tool is “internal” frequently turns out to be the only control in place.
What to do now
- Inventory the affected device classes. List the printers, smart home and AV kit, and AI tooling on your network, including Brother, Canon and Lexmark multifunction devices. Cyber Essentials expects you to know what is in scope before you can secure it.
- Watch vendor advisories over the next 90 days. Subscribe to security bulletins from Google, Samsung, the printer manufacturers and any AI platform vendors you use, and schedule firmware updates as they land. This maps directly to the Cyber Essentials security update management control.
- Segment embedded devices. Put printers and IoT kit on their own VLAN with tightly controlled inbound access, so a compromised device is not a pivot into the corporate network. This supports the firewalls control.
- Change default credentials and disable unused services. Hard-coded credentials cannot be fixed by you, but default admin passwords and unnecessary web or remote management interfaces can. This is core secure configuration.
- Keep mobile fleets current. Enforce minimum OS and security patch levels through your mobile device management platform for Pixel and Galaxy handsets.
- Bring AI tooling into change control. Treat model gateways, vector databases and coding agents as production systems with authentication, logging and patching, not developer experiments.
Bottom line
Pwn2Own Ireland 2026 delivered a bigger haul than last year and confirmed that phones, printers, smart home kit and AI infrastructure all carry exploitable flaws today. The prize money is the headline, but the work for UK defenders starts now: know where these devices are, segment them, and be ready to patch as the fixes arrive.
Sources
- Zero Day Initiative: Pwn2Own Ireland 2026 – Day Three Results and Master of Pwn
- Zero Day Initiative: Pwn2Own Ireland 2026 – Day Two Results
- BleepingComputer: Hackers get $1,262,000 for 98 zero-days at Pwn2Own Ireland
- BleepingComputer: Hackers exploit 32 zero-days on first day of Pwn2Own Ireland
- CyberInsider: Google Pixel 10 hacked as Pwn2Own Ireland wraps with $1.26 million in rewards
- GOV.UK: The UK Product Security and Telecommunications Infrastructure (PSTI) product security regime
- The Record: UK moves to shield security researchers in cybercrime law overhaul