The Pwn2Own Ireland 2026 hacking competition, hosted in Cork by Trend Micro's Zero Day Initiative, has concluded after researchers successfully demonstrated 98 distinct zero-day exploits. The event awarded over $1.2 million in prize money to ethical hackers for discovering and demonstrating vulnerabilities in a wide range of products, including smartphones, printers, smart home devices, and AI-powered applications. The Google Pixel 10 smartphone was a particularly popular and high-value target, accounting for $560,000 of the total prize pool. The competition serves as a critical mechanism for identifying and responsibly disclosing vulnerabilities to vendors, allowing them to develop patches before the flaws are discovered and used by malicious actors.
Pwn2Own is a series of computer hacking contests held several times a year, focusing on different technology categories. The Ireland 2026 event brought together security researchers from around the world to test the security of various devices and software. The first day alone saw the disclosure of 32 zero-day vulnerabilities, with participants earning over $368,000.
The high number of successful exploits (98) demonstrates that even mature products from major vendors contain serious, undiscovered security flaws. The significant financial rewards provide a powerful incentive for researchers to participate in coordinated disclosure programs rather than selling exploits on the black market.
While specific technical details of the 98 vulnerabilities are not made public immediately to give vendors time to create patches, the targets included a broad spectrum of modern technology:
All vulnerabilities demonstrated at Pwn2Own are disclosed to the affected vendors, who then have a set period (typically 90 days) to release a security patch. After the patch is available, the Zero Day Initiative may publish a technical write-up of the vulnerability.
The discovery of 98 zero-days in a single event underscores the persistent and widespread nature of software vulnerabilities. For enterprises and consumers, it serves as a reminder that no device is immune to exploitation. The event's findings will lead to a wave of security patches over the next few months, which will be critical for organizations to apply promptly.
The success of Pwn2Own reinforces the value of bug bounty programs and ethical hacking competitions. By creating a legal and lucrative channel for vulnerability research, these programs help secure the digital ecosystem for everyone. The high payouts, especially for mobile devices, reflect the complexity and potential impact of such exploits.
While the specific vulnerabilities are not yet public, organizations can take proactive steps:
The primary mitigation for the discovered zero-days will be to apply the patches released by vendors.
Mapped D3FEND Techniques:
The most direct and effective countermeasure for the 98 zero-day vulnerabilities discovered at Pwn2Own is to apply the forthcoming security patches from the affected vendors. Organizations should immediately identify all potentially affected assets in their environment, including the Google Pixel 10, smart home devices, printers, and any software using the targeted AI frameworks. Subscribe to security advisory notifications from these vendors to receive alerts as soon as patches are released. Prioritize deployment based on asset criticality and exposure, with internet-facing or highly sensitive devices being patched first. A robust and rapid patch management process is the only way to remediate these specific, now-known-to-be-exploitable flaws.
Pwn2Own Ireland 2026 competition begins, with 32 zero-days found on the first day.
The competition concludes with a total of 98 zero-days discovered and over $1.2 million awarded.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.