Five targets, five breaks
Pwn2Own Ireland 2026 ran from 6 to 8 October, and its AI infrastructure category did not have a good week. Across the Zero Day Initiative’s own daily write-ups, every named target in that category was exploited at least once.
On day one, LiteLLM went down twice: Taisic Yun of Xint chained improper input validation with code injection for $40,000 and four Master of Pwn points, and HaeJung Yang and ByungYoung Yi of Out of Bounds followed with four bugs, two of them previously known, for $15,000. Ikotas Labs took OpenAI Codex with an argument injection for $40,000. VinSOC combined five bugs against Oracle’s Autonomous AI Database for $40,000.
On day two, HaeJung Yang of Out of Bounds took Dynamo for $40,000 and four points. Team MAMMOTH broke Chroma with one zero-day and two collisions for a net $12,000, and Alessandro Fanio Gonzalez followed with two n-days and a collision for $4,500. Oracle’s database fell twice more — Taisic Yun for $14,000, and Ikotas Labs with a seven-bug chain ending in a use-after-free and a type confusion for $10,000.

Day three, and the trophy
The day three results kept the pattern. OtterSec took Oracle’s Autonomous AI Database with a four-bug chain — three collisions and one zero-day — for $6,250, and Platform Security did it again with five bugs for $6,000.
The competition itself was won elsewhere. Ikotas Labs took Google’s Pixel 10 for $300,000 and 30 Master of Pwn points, which made them Master of Pwn.
The bugs are not new, which is the point
Read the technique list and nothing about it is AI-specific: argument injection, improper input validation, code injection, use-after-free, type confusion. These are the classes that have been eating web applications since before most of the targets existed.
That is the finding. The AI serving stack — a model gateway, a vector database, an inference server, a coding agent, a managed database — has been assembled fast, mostly out of young open-source projects, and it is reproducing the vulnerability profile of the software it sits on top of. The argument injection against OpenAI Codex is worth singling out: an agent that reads a repository is a program that takes attacker-controlled input by design.

What happens next
Vendors generally get 90 days from Pwn2Own before the Zero Day Initiative discloses details publicly. That window is the useful thing here: the bugs exist now, the patches do not, and the list of affected components is published.
The thing to watch is which of the five ships a fix inside the window. A coding agent and a managed database have very different release cadences from a community vector store, and the gap between them is where the risk sits.