Hackers Earn $1,262,000 for 98 Zero-Days at Pwn2Own Ireland 2026
Competition highlights pervasive vulnerabilities across major platforms as researchers chain exploits for maximum impact

Key Takeaways
- Pwn2Own Ireland 2026 awarded $1,262,000 to hackers for exploiting 98 zero-day vulnerabilities.
- Researchers chained multiple exploits across browsers, operating systems, and IoT platforms to maximize impact and prize payouts.
- Specific affected products and CVE assignments are pending coordinated disclosure with vendors.
- The competition highlights the continued prevalence of zero-day vulnerabilities across widely used software and devices.
- Participants and organizers are working with vendors to ensure responsible disclosure and remediation.
Quick answers
- What happened?
- At the Pwn2Own Ireland 2026 hacking contest, participants collected $1,262,000 in rewards after successfully exploiting 98 zero-day vulnerabilities across various platforms. The event, which concluded on October 9, 2026, saw researchers chain multiple exploits to compromise target systems, with prize money distributed according to exploit complexity and chain length. Organizers and participants are coordinating findings with affected vendors for CVE assignment and remediation.
- What should defenders do?
- Organizations should ensure all software is updated to the latest patched versions. Prioritize patching of internet-facing products and browsers. Monitor vendor advisories for coordinated disclosures arising from Pwn2Own findings. Implement network segmentation and endpoint detection to reduce exploit impact.
The Pwn2Own Ireland 2026 hacking contest has concluded, with hackers collecting $1,262,000 in rewards after exploiting 98 zero-day flaws. According to reports from BleepingComputer, the event held in Ireland saw participants successfully compromise multiple platforms through chained vulnerabilities, earning significant prize payouts. The total of 98 zero-days exploited represents one of the largest yields in recent Pwn2Own history, reflecting the ongoing challenge of securing modern software ecosystems. Researchers leveraged a combination of browser, operating system, and IoT vulnerabilities to build multi-step exploit chains, with awards scaled to the complexity and impact of each chain. Specific affected products and corresponding CVE assignments are pending coordinated disclosure between researchers and vendors. The competition underscores the persistent risk posed by zero-day vulnerabilities and the importance of proactive patching and security research in identifying and remediating flaws before they can be exploited maliciously.
Security Details
Researchers exploited 98 zero-day vulnerabilities across various platforms during the Pwn2Own Ireland 2026 competition. Exploits were chained across browser, operating system, and IoT targets. Prize money was awarded based on exploit complexity and chain length. Full vulnerability details and CVE assignments are pending coordinated disclosure with affected vendors.
Mitigation
Organizations should ensure all software is updated to the latest patched versions. Prioritize patching of internet-facing products and browsers. Monitor vendor advisories for coordinated disclosures arising from Pwn2Own findings. Implement network segmentation and endpoint detection to reduce exploit impact.
Sources
BleepingComputer
Hackers get $1,262,000 for 98 zero-days at Pwn2Own Ireland
Oct 9, 2026 · 05:41
Original link
Related Security News

Citrix Issues Urgent Advisory for Critical NetScaler RCE Vulnerability
Citrix has warned IT administrators to patch systems immediately against a new critical vulnerability affecting NetScaler ADC networking appliances and NetScaler Gateway secure remote access solutions. The flaw is classified as critical severity with potential for unauthenticated remote code execution. Security updates have been released and administrators are urged to apply patches without delay.

GoBalance Vulnerability Enables .onion Address Hijacking via Secret Key Recovery
Searchlight Cyber disclosed a vulnerability in GoBalance, a tool used by dark-web sites to maintain availability during attacks. The flaw allows an attacker to recover the secret key controlling a .onion address using only public information, enabling address hijacking and redirection of visitors to attacker-controlled copies.



