On 6 Oct 2026, researchers exploited 32 zero-day vulnerabilities in the Samsung Galaxy S26 on the first day of Pwn2Own Ireland. This effort alone earned them $388,500. Despite these alarming discoveries, the second day of the competition saw the list grow further. On 8 Oct 2026, an additional 45 zero-day vulnerabilities were exploited, bringing the total count to 77 zero-days for the Samsung Galaxy S26. Researchers, on this second occasion, earned $232,500. According to the event organizers, each successful exploit highlights significant flaws in the phone's security defenses, presenting immediate challenges for cybersecurity professionals and consumers who rely on the S26 as their primary device.
What happened
The competition began on October 6 at Pwn2Own Ireland 2026. On the first day, researchers focused on the Samsung Galaxy S26, exploiting 32 zero-day vulnerabilities in two separate hacks, writes BleepingComputer.
On the second day, October 7, the exploits continued. Experts discovered another 13 zero-day vulnerabilities in the Galaxy S26. They successfully attacked the device three times.
These findings made the Galaxy S26 the single most targeted device at the competition, according to BleepingComputer.
Each successful hack earned the researchers cash rewards, totaling $232,500 for the day.
By the end of the second day, the total number of zero-day vulnerabilities exposed in the Galaxy S26 reached 45. These findings highlight the extent to which even the latest mobile devices can be vulnerable to exploitation.
[expand with more concrete details]
The team from a security startup, FlingSquad, was particularly impressive. They managed to exploit vulnerabilities via WiFi, and they were the first to exploit a zero-day flaw within the device's SecureWorld partition on the first day.
The attacks were not limited to just zero-day vulnerabilities. Some researchers also found ways to exploit previously patched vulnerabilities that were still exploitable due to incomplete patches. For example, a new attack technique was discovered, combining multiple old vulnerabilities to bypass modern security features.
The Pwn2Own Ireland competition is organized by Trend Micro’s Zero Day Initiative, a program focused on finding and patching software vulnerabilities. The event provides a platform for security researchers to demonstrate their skills and earn significant rewards.
This year, the event drew more than 100 researchers from 22 countries. BleepingComputer detailed how the first day of exploits showed the increasing sophistication of mobile device attacks, noting that the researchers were able to bypass multiple layers of security to gain unauthorized access to the devices.
It is interesting to note that even before the latest exploits, Samsung’s devices had never been a stranger to Pwn2Own competitions. In the past, they usually appeared as targets in such events, underlining just how popular they are among cybersecurity pros for bug hunting.
Why it matters This discovery has serious implications for businesses and IT teams. Zero-day vulnerabilities, like those targeted in the Samsung Galaxy S26, pose significant risks. Once exploits are known, any device or platform targeted becomes a high-priority area for cyber attackers. According to BleepingComputer, exploits like those used on the S26 can create pathways for data breaches, identity theft, and unauthorized access to sensitive information. The Samsung Galaxy S26 vulnerabilities highlight a real danger for mobile-centric operations. Many businesses rely on mobile devices for customer interactions, data management, and internal communication. If a device commonly in use falls into insecure status, the effects can be cascading. The exploitation of such vulnerabilities can quickly propagate through corporate networks, embedding deeper breaches than just the immediate device. For example, a compromised Galaxy S26 could allow unauthorised access to a corporate network. This breach could lead to the theft of intellectual property for competitors, sensitive internal communications revealed, financial loss through fraudulent activities, and damage to brand reputation. When devices like smartphones have undetected zero-day vulnerabilities, cybersecurity teams often need to react on short notice. This reactive stance can strain resources, as patching must be prioritized and rolled out swiftly. The sheer volume of zero-day vulnerabilities uncovered in events like the Pwn2Own contest indicates that companies must be prepared for a steady stream of patches and updates. IT security must shift from a reactive mode to a preventative state. Regular vulnerability assessments and proactive security measures become non-negotiable. Security teams will increasingly have to adopt comprehensive monitoring tools to identify irregular activity as soon as it occurs. This heightened vigilance can help detect and mitigate zero-day exploits. A shift to continuous monitoring protocols ensures that any unusual behaviour is flagged and analyzed immediately. Furthermore, the Pwn2Own revelation underscores the importance of device management policies. Businesses using mobile devices must enforce strict policies for access control, secure app usage, and regular security audits. By doing so, companies can reduce their attack surface and mitigate the impact of any potential zero-day exploits. Moreover, this event serves as a reminder that security awareness training for employees is vital. Employees who understand the risks and know how to identify suspicious activities can act as an additional layer of defense. Regular updates and patches, coupled with robust cybersecurity practices and comprehensive monitoring, can significantly reduce the threats posed by zero-day vulnerabilities. This not only ensures smoother operations but also safeguards data integrity and business continuity.What to do
- Ensure all Samsung Galaxy devices are updated with the latest security patches to protect against known vulnerabilities.
- Keep an eye on security bulletins and advisories from Samsung and other relevant authorities to stay informed about new vulnerabilities.
- Regularly audit your mobile security policies and ensure they are up-to-date, reflecting the latest threats and best practices.
- Educate employees on phishing and social engineering attacks, emphasizing the importance of not downloading untrusted apps or clicking on suspicious links.
- Implement comprehensive security software on all devices to monitor for and mitigate any potential threats.
2TI lens
The Pwn2Own event showcases the constant arms race between hackers and manufacturers. A Spatial Digital Agency approach involves creating secure environments from the ground up, much like how device manufacturers may need to rethink their processes to address such vulnerabilities more proactively.
Such events highlight the immediate need for continuous threat monitoring and patching, which a PaaS approach can support by facilitating ongoing updates and integrations.
Sources
- BleepingComputer,
During Pwn2Own Ireland 2026, security researchers targeted the Samsung Galaxy S26 intensively. BleepingComputer reported that on the second day of the event, researchers exploited 45 unique zero-day vulnerabilities, earning $232,500 (2026-10-08). Additionally, on the first day, they hacked the device twice, exploiting 32 zero-day vulnerabilities and securing $388,500 (2026-10-06). The extensive exploitations highlight the critical vulnerabilities present in the device, posing significant risks to users who do not update their systems promptly.