Back to Intelligence

Pwn2Own Ireland 2026: 98 Zero-Days, $1.26M Paid Out — What Defenders Must Do While Patches Are Pending

SA
Security Arsenal Team
October 9, 2026
8 min read

Security researchers walked away from Pwn2Own Ireland 2026 with $1,262,000 after demonstrating 98 previously unpatched vulnerabilities across consumer and enterprise hardware categories. Every one of those flaws now sits in a coordinated-disclosure window — typically 90 days under Trend Micro/ZDI rules — during which the bug exists, the vendor knows about it, and you do not have a patch. That window is your exposure, and this post is about surviving it.

Introduction: Why a Hacking Contest Is a Defensive Emergency

Pwn2Own is often misread as a research spectacle. From a defender's seat, it is a leading indicator of your near-term patch workload and attack surface risk. The 98 zero-days disclosed in Ireland are now in the hands of ZDI and the affected vendors — but history tells us two uncomfortable truths. First, some vendors will blow the 90-day window and the details will go public unpatched. Second, the exploit techniques demonstrated at Pwn2Own — particularly those targeting SOHO routers, NAS appliances, smart home hubs, printers, and EV charging infrastructure — frequently share primitives with vulnerabilities already circulating in criminal and state-sponsored tooling.

You do not have CVE numbers yet for most of these. That is precisely the point. Your job over the next 90 days is compensating controls, inventory discipline, and detection posture — not waiting for a patch list.

Technical Analysis

What was demonstrated

Pwn2Own Ireland focuses on the device categories that sit at the soft underbelly of enterprise and home networks:

  • SOHO routers and network edge devices — historically the highest-payout category and the most operationally dangerous. Edge devices are the first hop for botnets (think of the recurring Mirai-variant and proxy-network campaigns) and are notoriously slow to receive patches from vendors.
  • NAS appliances — QNAP and Synology-class devices have been ransomware targets for years. A remote code execution zero-day in a NAS is not a data-loss event; it is a data-extortion event.
  • Printers and imaging devices — still the least-monitored computers on your network, with full Active Directory adjacency in most environments.
  • Smart home / IoT hubs and EV chargers — increasingly relevant as corporate fleets and executive home offices blur the perimeter.

Exploitation status

  • Public exploit code: Not yet. ZDI purchases exclusive disclosure rights and coordinates with vendors. Detailed write-ups and, eventually, CVE assignments will follow over the coming weeks and months.
  • In-the-wild exploitation: None confirmed for these specific findings — by design. However, assume partial technique overlap with known exploit chains targeting the same device classes.
  • CISA KEV: Watch this closely. Historically, Pwn2Own-disclosed bugs in edge devices have landed in the KEV catalog within weeks of public disclosure when vendors slip or details leak.

The defender's mental model

Treat every unpatchable-window zero-day as a pre-positioning problem. The exploitation prerequisites for most of these device-class bugs are: (1) network reachability to the management interface, (2) an unauthenticated or low-authentication attack surface, and (3) a vulnerable parsing or service component. You cannot fix (3) today. You can absolutely fix (1) and (2) today.

Detection & Response

While vendor-specific indicators do not yet exist, the post-exploitation behavior of a compromised edge or IoT device is highly consistent: unexpected child processes from service binaries, outbound connections from devices that should never initiate internet traffic, and management-plane logins from unusual sources. These are the behaviors worth hunting now.

YAML
---
title: Network Service Process Spawning Shell or Download Utility
id: 3f8a1c42-7b2d-4e91-a6c3-9d5e2f8b1a04
status: experimental
description: Detects shell or download utility execution spawned by network service processes, consistent with post-exploitation behavior observed after edge/NAS/IoT device compromise via service parsing flaws such as those demonstrated at Pwn2Own.
references:
  - https://www.zerodayinitiative.com/blog/
  - https://attack.mitre.org/techniques/T1059/
author: Security Arsenal
date: 2026/04/06
tags:
  - attack.execution
  - attack.t1059
  - attack.t1105
logsource:
  category: process_creation
  product: windows
detection:
  selection_parent:
    ParentImage|endswith:
      - '\spoolsv.exe'
      - '\svchost.exe'
      - '\httpd.exe'
      - '\nginx.exe'
      - '\w3wp.exe'
  selection_child:
    Image|endswith:
      - '\cmd.exe'
      - '\powershell.exe'
      - '\pwsh.exe'
      - '\certutil.exe'
      - '\curl.exe'
      - '\wget.exe'
      - '\bitsadmin.exe'
  condition: selection_parent and selection_child
falsepositives:
  - IIS application pools legitimately invoking scripts (tune per application pool identity)
  - Print driver installation activity during software deployment windows
level: high
---
title: Edge or IoT Device Initiating Outbound Internet Connection
id: 8b2e5d17-4c6a-4f38-b192-7e3d9a5c2f60
status: experimental
description: Detects outbound internet connections from device classes (printers, NAS, cameras, IoT hubs) that have no legitimate business initiating arbitrary internet sessions. A compromised device almost always phones home or pulls second-stage tooling.
references:
  - https://attack.mitre.org/techniques/T1071/
  - https://attack.mitre.org/techniques/T1105/
author: Security Arsenal
date: 2026/04/06
tags:
  - attack.command_and_control
  - attack.t1071
logsource:
  category: network_connection
  product: windows
detection:
  selection:
    Initiated: 'true'
    DestinationIsIpv6: 'false'
  filter_rfc1918:
    DestinationIp|startswith:
      - '10.'
      - '172.16.'
      - '172.17.'
      - '172.18.'
      - '172.19.'
      - '172.2'
      - '172.30.'
      - '172.31.'
      - '192.168.'
  condition: selection and not filter_rfc1918
falsepositives:
  - Legitimate firmware update and cloud-telemetry traffic — baseline per device class and alert on deviation, not raw matches
level: medium
KQL — Microsoft Sentinel / Defender
// Hunt: Devices on IoT/edge VLANs initiating outbound connections to uncommon destinations
// Requires firewall/NSG flow logs or Sysmon network events ingested into Sentinel.
// Tune the DeviceSubnet list to your actual IoT/edge segments.
let IoTSubnets = dynamic(["10.50.", "10.60.", "192.168.30."]);
let KnownVendorCDNs = dynamic(["qnap.com", "synology.com", "microsoft.com", "amazonaws.com", "akamai"]);
DeviceNetworkEvents
| where TimeGenerated > ago(7d)
| where ActionType == "ConnectionSuccess"
| where IoTSubnets has (LocalIP) or DeviceName has_any ("printer", "nas", "cam", "iot")
| where not (RemoteIP startswith "10." or RemoteIP startswith "192.168." or RemoteIP startswith "172.16.")
| where not (RemoteUrl has_any (KnownVendorCDNs))
| summarize ConnectionCount=count(), FirstSeen=min(TimeGenerated), LastSeen=max(TimeGenerated),
    RemoteIPs=make_set(RemoteIP), RemoteURLs=make_set(RemoteUrl)
  by DeviceName, LocalIP, InitiatingProcessFileName
| order by ConnectionCount desc
VQL — Velociraptor
-- Hunt: Inventory listening services and unexpected outbound connections on endpoints
-- Run across your fleet to identify appliances and services exposed beyond their intended scope
SELECT Pid, Name, Status, Family, Laddr, Raddr,
       process_name() as ProcessName
FROM netstat()
WHERE Status =~ 'LISTEN'
   OR (Family =~ 'tcp'
       AND NOT Raddr =~ '^(10\\.|192\\.168\\.|172\\.(1[6-9]|2[0-9]|3[01])\\.|127\\.)')
PowerShell
# Verify and harden: edge/IoT exposure audit script
# Run from a management host against your device inventory.

# 1. Enumerate network devices responding on common management ports
$targets = Get-Content "C:\inventory\edge-devices.txt"
$mgmtPorts = @(80, 443, 23, 21, 8080, 8443, 5000, 5001, 9000)
foreach ($t in $targets) {
    foreach ($p in $mgmtPorts) {
        $r = Test-NetConnection -ComputerName $t -Port $p -WarningAction SilentlyContinue
        if ($r.TcpTestSucceeded) {
            [PSCustomObject]@{ Device=$t; Port=$p; Open=$true } |
                Export-Csv "C:\audit\open-mgmt-ports.csv" -Append -NoTypeInformation
        }
    }
}

# 2. Check whether management interfaces are reachable from user VLANs (they should not be)
#    Compare against your segmentation policy — flag any device reachable on 23/21 (telnet/FTP)
Import-Csv "C:\audit\open-mgmt-ports.csv" |
    Where-Object { $_.Port -in @(21,23) } |
    ForEach-Object { Write-Warning "INSECURE PROTOCOL EXPOSED: $($_.Device):$($_.Port) — disable immediately" }

# 3. Pull current firmware versions from QNAP/Synology via their CLIs (SSH) or SNMP,
#    and diff against vendor security advisory pages weekly during the disclosure window.

Remediation: Operating Through the 90-Day Window

You cannot patch what has not been released. You can, however, render most of these bugs unreachable. Priorities, in order:

  1. Kill management-plane exposure. No router, NAS, printer, or IoT hub management interface should be reachable from the internet, and ideally not from general user VLANs. Audit UPnP on every edge device and disable it — UPnP-mediated port exposure is a recurring root cause in SOHO device compromise.
  2. Enforce egress restrictions on device VLANs. Printers and NAS appliances need to talk to a defined set of update servers, not the internet. A default-deny egress policy on IoT/edge segments neutralizes the most common post-exploitation step (payload retrieval and C2).
  3. Inventory and version-pin everything. You cannot respond to a CVE drop for a device you forgot you own. Build the asset list now: make, model, firmware version, network location, internet reachability.
  4. Monitor the ZDI disclosure pipeline. ZDI publishes upcoming advisory IDs before full details drop. Subscribe to the ZDI advisory feed and your vendors' PSIRT pages; when advisories publish, you should be patching within 48 hours for edge devices.
  5. Watch CISA KEV weekly. If any of these 98 findings — or near-neighbor bugs in the same products — hit KEV, federal remediation deadlines (typically 3 weeks under BOD 22-01) are a reasonable private-sector benchmark too.
  6. Rotate credentials on device-adjacent services. NAS appliances and printers commonly store LDAP/AD service account credentials. If a device is later confirmed vulnerable to unauthenticated RCE, assume those credentials were exposed.
  7. Plan the patch surge. 98 zero-days means a concentrated vendor patch cycle over the next 60–90 days. Pre-stage maintenance windows and test rings now so you are not negotiating change control while exploit code circulates.

The Bigger Picture

Pwn2Own payouts keep climbing because device-class software remains the weakest link in most environments. $1,262,000 for 98 flaws is not a research curiosity — it is a market signal that your printers, routers, and storage appliances are softer targets than your patched, EDR-covered endpoints, and adversaries know it. The organizations that fare best when these CVEs finally drop will be the ones that used the disclosure window to shrink reachability, tighten egress, and build the inventory. Do that work this week.

Related Resources

Security Arsenal Penetration Testing Services AlertMonitor Platform Book a SOC Assessment vulnerability-management Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.