Researchers Exploit 32 Zero-Days on First Day of Pwn2Own Ireland 2026
Samsung Galaxy S26 devices compromised; $388,500 in prize money awarded

Key Takeaways
- 32 zero-day vulnerabilities were exploited across two Samsung Galaxy S26 devices on the first day of Pwn2Own Ireland 2026.
- Security researchers earned $388,500 in prize money for successful hacks.
- The exploits underscore the persistent risk of zero-day vulnerabilities in mobile operating systems.
- Coordinated disclosure is likely underway; public patches for the specific exploits are not yet available.
Quick answers
- What happened?
- On the first day of the Pwn2Own Ireland 2026 competition, security researchers successfully hacked two Samsung Galaxy S26 devices by exploiting 32 zero-day vulnerabilities, earning a combined $388,500 in prize money. The exploits demonstrate the prevalence of unpatched vulnerabilities in modern mobile platforms.
- Which products are affected?
- Samsung Galaxy S26
- What should defenders do?
- Users should ensure their Samsung Galaxy S26 devices are running the latest available software updates. Samsung is likely releasing security patches as part of coordinated disclosure with researchers. It is advisable to monitor official Samsung security advisories for patch availability.
BELFAST/ DUBLIN - On the first day of the Pwn2Own Ireland 2026 competition, security researchers hacked two Samsung Galaxy S26 devices by exploiting a total of 32 zero-day vulnerabilities, earning $388,500 in prize money. The contest, which pits hackers against cutting-edge technology, saw the Samsung Galaxy S26 targeted multiple times. While the exact technical details of the vulnerabilities remain under embargo pending coordinated disclosure, the scale of exploits highlights ongoing challenges in mobile device security. Samsung and the participating researchers are likely engaged in coordinated vulnerability disclosure processes. As of now, no public patches are available for the newly exploited zero-days. The competition continues over subsequent days, with further exploits expected.
Security Details
Multiple zero-day vulnerabilities were exploited to compromise Samsung Galaxy S26 devices. Specific CVE identifiers and technical exploit details have not been publicly disclosed pending coordinated vulnerability disclosure. The exploits were executed during a sanctioned security competition context.
Affected products
Samsung Galaxy S26
Mitigation
Users should ensure their Samsung Galaxy S26 devices are running the latest available software updates. Samsung is likely releasing security patches as part of coordinated disclosure with researchers. It is advisable to monitor official Samsung security advisories for patch availability.
Sources
BleepingComputer
Hackers exploit 32 zero-days on first day of Pwn2Own Ireland
Oct 6, 2026 · 19:21
Original link
Related Security News

LibreOffice and OpenOffice Java Flaw Enables Silent Code Execution via Malicious Spreadsheets
Security researchers have demonstrated a proof-of-concept attack affecting LibreOffice and Apache OpenOffice that allows malicious spreadsheets to execute attacker code upon file opening without triggering the macro warnings typically displayed by the applications. The vulnerability requires Java support to be enabled within the office suites to function.




