Pwn2Own Ireland Uncovers 32 Zero-Day Flaws in a Single Day, Including in AI Tools
Ethical hackers gathered in Cork, Ireland, for Pwn2Own Ireland 2026, which began on October 6. On the first day, teams targeted smartphones, smart home devices, printers and AI tools such as OpenAI Codex and LiteLLM. They uncovered 32 zero-day vulnerabilities (flaws unknown to the vendor) and earned more than $368,000 in prize money. The Master of Pwn winner will be announced after the event ends on October 8.
As part of the Zero Day Initiative, findings are responsibly disclosed to the affected vendors, who then have 90 days to release updates before the details are published. The article notes that such contests matter more than ever, as vendors struggle to find flaws in their products before adversaries do.
The figures cited from Google show the pressure building. Vulnerability disclosures reportedly rose from 5,045 in January 2026 to 10,740 in August 2026, and exploited vulnerabilities rose from an average of 10.5 a month in 2025 to 18 a month so far in 2026. Google also found that 50% of flaws it identified as likely AI-discovered allowed remote code execution, compared with 26% of other CVEs. However, separate research claims only 1% of AI-discovered vulnerabilities have been exploited in the wild.