4 MIN READ
The market for working exploits on major software platforms now sits in the seven figure range per buyer, per vulnerability, and the supplier side has matured into a small number of professional brokers. That is where the zero day economy stands in 2026. The defender who assumes the major platform the company runs on has a working exploit in someone else’s hands is the defender who survives the year.
Lineage worth knowing. Zerodium, the largest public broker, publishes a price list that runs up to $2.5M for a full chain remote code execution exploit on iOS. CrowdStrike’s Falcon Adversary Shop and Mandiant’s broker network sit in the same bracket. A second tier of boutique brokers, mostly Russian and Israeli, competes on access to specific platforms and faster payouts. The buyer side is the usual cast: the NSA, the GCHQ, the FSB, the MSS, the DGSE, plus the criminal groups, the private offensive security firms, and a small research buyer market. The deals happen quietly, but the price list is public enough to anchor the conversation.
How the prices break down
The price tiers map to the value of the access the exploit gives the buyer. A full chain exploit, where the attacker has a working end to end attack (initial access, privilege escalation, persistence, exfiltration) on a major platform (iOS, Android, Windows, macOS), commands $1M to $2.5M per exploit. A single click remote code execution, where the victim only has to click once before code executes, drops to $500K to $1M. A local privilege escalation, where the attacker is already on the box and just needs to escalate from standard user to system, runs in the $100K to $500K range. Information disclosure exploits (the credential dump, the session token leak, the location data grab) clear $50K to $200K. Denial of service, the loudest and least valuable category, runs $10K to $50K. The same shape, just at different stakes.
Who buys what, and why it matters to the defender
The state buyer purchases exploits the agency cannot develop in house, usually for offensive operations that require an access path no defensive research team has noticed yet. The criminal buyer purchases exploits to deploy against enterprise targets, usually through a ransomware crew or an initial access broker who parcels the access out to the highest bidder. The private offensive security buyer purchases exploits for legitimate red team engagements, where the client has paid for the realistic test the internal team could not run. The research buyer is small in dollar terms but large in signal: when Project Zero or a similar academic team buys an exploit, the defensive intelligence tends to follow the disclosure within months. The private market, the deals that never appear on a public price list, is at least as large as the public market. Nobody publishes those numbers, which is the part the defender should sit with.
What the defender does
Assume any major platform the company runs on has a working zero day in someone else’s hands. The price list suggests the supply exists. The broker network suggests the supply reaches the buyers. Defence in depth is the only response that survives the assumption.
Defend accordingly. Zero trust, network segmentation, behavioural detection. None of these stop the working exploit on its own, but layered together they make the single working exploit a recoverable incident rather than a catastrophic one. The cost of the layering is real. The cost of skipping it is higher.
Patch aggressively, on a clock measured in days rather than weeks. The window between a vendor advisory and an exploit being weaponised at scale has shrunk from months in 2018 to weeks in 2026. The company that patches inside 72 hours of a vendor advisory usually avoids the average zero day. The company that runs a 30 day change window often meets the weaponised version first.
Monitor for the exploitation patterns the threat intelligence feeds publish. When a zero day gets weaponised at scale, the indicators tend to show up in the threat intel within weeks. The defender who subscribes to the right feeds, watches for the patterns, and tightens the detection rules on the signal usually catches the exploitation before the damage spreads.

The bottom line
Assume the zero day exists, defend in depth, patch on a 72 hour clock, monitor for the patterns. The defender who treats the zero day as a real and present input is the defender who still has the data at the end of the year.
Sources & Further Reading
All claims in this article are sourced from primary documentation, vendor advisories, and reputable security researchers.
Spotted an error? Email the editor. Corrections are issued with a visible correction note.
Editorial standards. Every article on humanrequired.org is reviewed by a human editor before publication. AI may assist with drafting or research; final editorial control is human. Read the full standards.



