Bug Bounty

Pwn2Own Ireland 2026 pays $1.26m for 98 zero-days

Pwn2Own Ireland 2026 paid $1.26m for 98 zero-days in phones, printers, smart home kit and AI tools. What UK organisations should do next.

Illustration of a software bug icon with the headline 98 zero-days paid out at Pwn2Own Ireland

Pwn2Own Ireland 2026 closed in Cork on 8 October with researchers paid $1,262,000 for 98 previously unknown vulnerabilities in phones, printers, smart home hubs and AI infrastructure. For UK organisations, the more useful takeaway is the patch wave that will follow over the next 90 days and what it says about the kit sitting on their own networks.

What happened

The Zero Day Initiative (ZDI) ran its third Pwn2Own contest in Ireland from 6 to 8 October, with the final results and the Master of Pwn standings published on 8 October. Across the three days, 29 teams made 61 completed attempts against targets in seven categories: mobile phones, messaging, smart home devices, printers, wellness devices, AI infrastructure and AI coding agents.

The running totals tell the story. According to BleepingComputer, the opening day produced 32 zero-days worth $388,500, the second day 45 worth $232,500, and the closing day 21 worth $641,000. That compares with roughly $1.02 million for 73 zero-days at the 2025 edition, so both the bug count and the prize pot rose year on year.

Ikotas Labs took the Master of Pwn title with $361,000 and 42.5 points, overtaking Xint late on the last day. Its decisive entry was a chained exploit against the Google Pixel 10 that earned $300,000 on its own. Xint finished second on $240,000, with Team ZyGoat third on $125,000. Nobody registered an attempt against Apple’s iPhone 17.

The technical picture

The Pixel 10 was the headline target and fell three times on the final day. Xint landed a remote compromise using a single bug, Ikotas Labs chained several issues, and a team combining Mobile Hacking Lab’s Djini.ai tooling with CENSUS Labs researchers paired a fresh zero-day with a known flaw for $112,500. Samsung’s Galaxy S26 was also compromised repeatedly across the week, including a final-day remote entry from BunkyoWesterns.

Much of the action, though, came from less glamorous categories. Home Assistant Green was the most attempted device on day two, and Team MAMMOTH closed the event with a six zero-day chain against it. The Philips Hue Bridge Pro, Sonos Era 300 and Garmin Index BPM wellness device were all exploited. In the printer category, a lone zero-day in a Brother MFC-L8970CDW won FuzzingLabs $20,000, while Canon and Lexmark devices also fell; Interrupt Labs marked its Lexmark success by running DOOM on the printer.

ZDI’s own day two notes describe one Canon imageFORCE chain as combining hard-coded credentials, a missing authentication check on a critical function and command injection. That is a depressingly familiar trio for anyone who tests embedded devices. On the AI side, Oracle’s Autonomous AI Database was breached by several teams, Dynamo and LiteLLM were exploited, and OpenAI’s Codex coding agent was taken down with a single bug on day one.

A recurring word in the results was “collision”. In Pwn2Own terms, that means an exploit worked but used a vulnerability that ZDI or the vendor already knew about, which lowers the payout. Many final-day chains, including the winning Pixel entry, contained collisions. Successful entrants hand their exploit details to ZDI, which passes them to vendors under a 90-day deadline before public disclosure.

Key figures from Pwn2Own Ireland 2026: $1.26m paid for 98 zero-days by 29 teams, Ikotas Labs Master of Pwn, 90-day vendor patch deadline

Why it matters for UK organisations

None of these targets are exotic. Brother, Canon and Lexmark multifunction printers sit in offices, schools and surgeries across the UK. Smart home hubs and speakers increasingly turn up in meeting rooms and small businesses, and the Pixel and Galaxy ranges are common corporate handsets. Every one of the 98 bugs now sits in a vendor queue, and the fixes will arrive as firmware and app updates over the coming weeks.

There is also a regulatory angle. Since 29 April 2024, the UK product security regime under the Product Security and Telecommunications Infrastructure Act 2022 has required manufacturers of consumer connectable products to publish a way to report vulnerabilities, set out timescales for acknowledging reports, and state a minimum security update period. Several of the device classes hacked in Cork fall squarely into that territory, so buyers can reasonably expect clear advisories and update commitments from vendors selling here.

The contest also lands while the UK is still waiting to see how the Computer Misuse Act 1990 will be rewritten. The government signalled the reform in May, but has not yet published draft legislation, and campaigners such as CyberUp are pressing for what they call a “clear, workable statutory defence” for good-faith research. Pwn2Own shows what structured, authorised research can deliver when the rules are clear.

Expert view

Pwn2Own is sometimes dismissed as a showcase, but I think it is one of the most honest signals in the industry. A cash prize only pays out for a working exploit demonstrated live, not a theoretical finding in a slide deck, and that discipline is exactly what bug bounty programmes try to replicate.

The collision count is the detail I would pay most attention to. When several teams independently arrive at the same flaw, that flaw is not hard to find. If professional researchers are converging on it, so can a capable criminal group, and the vendor’s existing fix pipeline becomes the real line of defence. In my experience, embedded devices such as printers and building controllers are where organisations are slowest to apply firmware updates, because nobody clearly owns them.

The AI infrastructure results deserve a mention too. Model gateways, vector databases and coding agents are being deployed quickly, often by development teams outside the normal change process. When we test environments like these, the assumption that a tool is “internal” frequently turns out to be the only control in place.

What to do now

  1. Inventory the affected device classes. List the printers, smart home and AV kit, and AI tooling on your network, including Brother, Canon and Lexmark multifunction devices. Cyber Essentials expects you to know what is in scope before you can secure it.
  2. Watch vendor advisories over the next 90 days. Subscribe to security bulletins from Google, Samsung, the printer manufacturers and any AI platform vendors you use, and schedule firmware updates as they land. This maps directly to the Cyber Essentials security update management control.
  3. Segment embedded devices. Put printers and IoT kit on their own VLAN with tightly controlled inbound access, so a compromised device is not a pivot into the corporate network. This supports the firewalls control.
  4. Change default credentials and disable unused services. Hard-coded credentials cannot be fixed by you, but default admin passwords and unnecessary web or remote management interfaces can. This is core secure configuration.
  5. Keep mobile fleets current. Enforce minimum OS and security patch levels through your mobile device management platform for Pixel and Galaxy handsets.
  6. Bring AI tooling into change control. Treat model gateways, vector databases and coding agents as production systems with authentication, logging and patching, not developer experiments.

Bottom line

Pwn2Own Ireland 2026 delivered a bigger haul than last year and confirmed that phones, printers, smart home kit and AI infrastructure all carry exploitable flaws today. The prize money is the headline, but the work for UK defenders starts now: know where these devices are, segment them, and be ready to patch as the fixes arrive.

Sources