As reported by BleepingComputer, the Pwn2Own Ireland 2026 competition concluded with 29 research teams demonstrating 98 unique zero-day vulnerabilities across mobile phones, AI infrastructure, smart home, and a newly introduced wellness healthcare category. The total payout of $1,262,000 represents a 23% increase over last year's prize pool, but the real story isn't the money — it's what the target list tells us about the evolving attack surface.
The AI Category Is No Longer Experimental
This year marked a notable shift: AI infrastructure and AI coding applications were prominent targets, with Ikotas Labs — the overall winner — successfully compromising OpenAI Codex and Oracle's Autonomous AI Database. That's significant. We're watching threat research move upstream from endpoint and mobile targets toward the development tooling and data backends that enterprises are rapidly adopting.
When AI coding assistants and autonomous databases become Pwn2Own targets, it signals the research community has identified them as materially exploitable — not theoretical — attack surfaces.
Oracle's Autonomous AI Database being compromised is particularly noteworthy. Autonomous databases are marketed on the premise of self-securing, self-patching infrastructure. A successful zero-day chain against that product challenges the assumption that automation alone reduces exposure. If the autonomy layer can be subverted, the underlying data — increasingly the crown jewel for AI-driven enterprises — is at risk.
Mobile Remains Deeply Fragmented
The Samsung Galaxy S26 was compromised at least five times across multiple teams and days, and the Google Pixel 10 was taken down three times on the final day alone. These are flagship devices running the latest firmware — Pwn2Own rules require it. The persistence of exploitable chains in hardened mobile operating environments reinforces what defenders already know: mobile remains one of the least mature segments of enterprise security programs despite carrying some of the most sensitive corporate data.
What the 90-Day Window Means for You
ZDI's policy requires vendors to patch within 90 days before public disclosure. That clock is now ticking. Organizations running any of the targeted products — particularly Samsung Galaxy S26, Google Pixel 10, OpenAI Codex, or Oracle Autonomous Database — should treat the next three months as a hardening sprint, not a waiting period.
The wellness healthcare category is also worth watching. Medical and wellness devices have historically lagged in patch cadence and vulnerability management. The introduction of this category at Pwn2Own suggests researchers are finding fertile ground there — and where researchers go, threat actors eventually follow.
Shield53 Recommendations
The 98% increase in zero-days demonstrated this year — up from 73 in 2025 — is not just more researchers showing up. It reflects a genuinely expanding attack surface where AI, mobile, and connected health converge. The organizations that treat this competition as an early warning system rather than a spectator event will be the ones with clean incident reports next quarter.