Security1 publisherNot yet confirmed elsewhere2 min readPublished
Pwn2Own Ireland's first day puts LiteLLM and OpenAI Codex among 32 exploited zero-days
Pwn2Own Ireland 2026 researchers exploited 32 zero-days on day one for $388,500, including LiteLLM flaws and an OpenAI Codex argument injection. Vendors now have 90 days to ship fixes before ZDI publishes details, and the report describes contest exploits only.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction
What happened
- The contest covers seven categories, with AI infrastructure and AI coding apps listed beside phones, printers, smart home, messaging apps and a new wellness healthcare category.
- Samsung's Galaxy S26 was hacked twice, with Interrupt Labs, Ikotas Labs and Viettel Cyber Security's Nguyen Thanh Dat named in the day's highlight.
- Researchers hacked two multifunction printers, the Lexmark CX532adwe and the Canon imageFORCE 1643F.
- A Sonos Era 300 smart speaker was compromised again, this time through a chain of four vulnerabilities.
- White Noise Club went after the Google Pixel 10 but could not get its exploit working within the allotted time.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure When ZDI publishes after the 90-day window, any LiteLLM deployment that has not taken the vendor's update will be running a flaw whose details are public.
- constraint Until the LiteLLM bugs are described, operators cannot rank them against the rest of their patch queue.
- precedent With AI infrastructure and AI coding apps set as contest categories, flaws in AI tooling can be expected to reach vendors through the same 90-day coordinated-disclosure route as phone and printer bugs.
The Codex entry is the one with a named bug class. According to BleepingComputer, a single argument-injection bug was enough to take down OpenAI's cloud-based coding agent [5]. The LiteLLM entry is thinner. The report says researchers demoed LiteLLM zero-days [4], without a count or a description of what the bugs allowed.
Rate these as working exploits under contest conditions. ZDI runs Pwn2Own to find zero-days in target products before threat actors can exploit them [9]. BleepingComputer describes the LiteLLM and Codex results as contest demonstrations and reports no use of either outside the event [4][5]. On this evidence, AI tooling is attack surface that prepared teams can break today.
Vendors have 90 days to release security updates before Trend Micro's ZDI publicly discloses the flaws [9]. Operators running LiteLLM are waiting on an update from the vendor inside that window.
Day one's 32 zero-days are about 44% of the 73 found across all of last year's Pwn2Own Ireland [12][14]. The $388,500 paid out is about 38% of last year's $1,024,750 [15]. Two days remain. AI infrastructure is on the schedule for both of them [10][11].
BleepingComputer says some of the bugs used in each Galaxy S26 challenge were already known to Samsung [13].
Teams brought working chains against AI infrastructure and an AI coding agent on the same day they brought them against phones and printers [4][5][6]. It shows where skilled researchers are spending contest time. Evidence that threat actors have made the same move would have to come from incident data.
What to watch
- Whether a LiteLLM security release ships before ZDI's 90-day disclosure deadline, and what bug classes the advisory names.
- Day two and day three AI infrastructure results, and whether the event total passes last year's 73 zero-days.
- Any report of the LiteLLM or Codex flaws being used outside the contest before ZDI publishes.