# Pwn2Own teams find 32 zero-day flaws, including exploits of Codex and LiteLLM

_Published Wednesday, October 7, 2026 at 11:10 PM EDT · Security · Latest · Tier 2 — Notable_

![Pwn2Own teams find 32 zero-day flaws, including exploits of Codex and LiteLLM — Primary](https://assets.infosecurity-magazine.com/webpage/og/d9cce03d-a6b0-4b61-b509-26403d871af7.jpeg)

Researchers found 32 previously undisclosed vulnerabilities on the first day of Pwn2Own Ireland on October 6, earning over $368,000 in prizes, Infosecurity Magazine reported. Targets included smartphones, smart home devices, printers and AI tools.

Ikotas Labs exploited OpenAI Codex through argument injection. Taisic Yun of Xint combined improper input validation and code injection to obtain a reverse shell on LiteLLM. VinSOC used five zero-day flaws to exploit Oracle Autonomous AI Database. The Zero Day Initiative discloses findings to vendors, giving them 90 days to release updates before publication.

## Sources

- [Infosecurity Magazine](https://www.infosecurity-magazine.com/news/pwn2own-hackers-32-zeroday/)

---
Canonical: https://techandbusiness.org/newswire/2TEo3ntfn3ICvQesCYVCsT
Published: 2026-10-08T03:10:53.501Z
Story chronology: 2026-10-06T00:00:00.000Z
Retrieved: 2026-10-08T05:42:45.905Z
Publisher: Tech & Business (techandbusiness.org)
