The Zero Day Economy in 2026: The Prices, the Buyers, the Deals

The zero day economy in 2026 sits at a $2B annual market, up from $300M in 2020, with the prices for the most valuable exploits reaching seven figures per buyer. The state of the zero day economy in 2026 amounts…

A single antique brass key on a dark velvet cushion, dim warm amber side light, deep navy shadows, no people visible.

The zero day economy in 2026 sits at a $2B annual market, up from $300M in 2020, with the prices for the most valuable exploits reaching seven figures per buyer. The state of the zero day economy in 2026 amounts to a market that has matured, professionalised, and consolidated into a few large players.

Zerodium, the largest public broker, pays up to $2.5M for a remote code execution exploit on iOS. The smaller brokers (CrowdStrike’s Falcon Adversary Shop, Mandiant’s broker network, the boutique Russian and Israeli brokers) pay similar amounts for similar exploits. The state-sponsored buyers (the NSA, the GCHQ, the FSB, the MSS, the DGSE) buy the exploits they cannot develop themselves. The criminal buyers buy the exploits they want to deploy against enterprise targets. The market runs in two tiers: the public brokers with public price lists, and the private brokers with private prices that nobody publishes. The 2026 state of the market amounts to a market that runs bigger, more professional, and more accessible than the market of 2020.

How the prices break down

Five tiers, in roughly that order of how much each tier pays. The first runs as the full chain exploit, where the attacker has a working exploit for a complete attack chain (initial access, privilege escalation, persistence, exfiltration) on a major platform (iOS, Android, Windows, macOS). The price ranges from $1M to $2.5M per exploit. The second tier runs as the single click RCE, where the attacker has a remote code execution exploit that fires on a single user click. The price ranges from $500K to $1M. The third tier runs as the local privilege escalation, where the attacker has an exploit that escalates from a standard user to system level. The price ranges from $100K to $500K. The fourth tier runs as the information disclosure, where the attacker has an exploit that leaks specific data (credentials, session tokens, location data). The price ranges from $50K to $200K. The fifth tier runs as the denial of service, where the attacker has an exploit that disrupts a service without gaining access. The price ranges from $10K to $50K. The five tiers together define the market.

Who buys what

Four buyer types, in roughly that order of how much each type spends. The first runs as the state sponsored buyer, where the intelligence agencies (NSA, GCHQ, FSB, MSS, DGSE) buy the exploits they cannot develop themselves, with the budget coming from the intelligence budget, with the procurement happening through the brokers. The state sponsored buyer purchases roughly 40% of the public market. The second runs as the criminal buyer, where the ransomware crews and the APT groups buy the exploits they want to deploy against enterprise targets, with the budget coming from the criminal proceeds, with the procurement happening through the brokers. The criminal buyer purchases roughly 30% of the public market. The third runs as the private offensive security buyer, where the offensive security firms (the legitimate red teams, the private intelligence firms) buy the exploits for client engagements, with the budget coming from the client engagement. The private buyer purchases roughly 20% of the public market. The fourth runs as the research buyer, where the academic researchers and the security researchers buy the exploits for the research, with the budget coming from the research grants. The research buyer purchases roughly 10% of the public market. The four buyer types together account for the public market. The private market (the exploits that never get sold publicly) runs at least as large.

What this means for the defender

Three moves if you are defending against the zero day economy in 2026. Assume any major platform has a working zero day in the hands of a state actor or a criminal actor, because the prices suggest the supply exists, and the brokers suggest the supply reaches the buyers. Defend accordingly, which means zero trust, network segmentation, behavioural detection, the defences that work even when the exploit works. Patch aggressively, because the window between the patch and the exploit being weaponised has shrunk from months to weeks. The enterprise that patches within 72 hours of a vendor advisory sits as the enterprise that does not lose to the average zero day. Monitor for the exploitation, because the zero days that get weaponised at scale show up in the threat intelligence within weeks. The enterprise that monitors for the exploitation patterns sits as the enterprise that catches the zero day before the damage spreads.

Abstract price tiers as glowing cyan columns of varying heights on a dark navy surface, dramatic chiaroscuro lighting from above.
Zero day economy in 2026: 5 price tiers, 4 buyer types, the $2B annual market. The defender who assumes the zero day exists, defends with zero trust, patches aggressively, and monitors for the exploitation stands as the defender who survives.

The bottom line

The zero day economy in 2026 sits at a $2B annual market with prices reaching $2.5M per exploit. The five tiers and the four buyer types define the market. The defender who assumes the zero day exists, defends with zero trust, patches aggressively, and monitors for the exploitation stands as the defender who survives the zero day economy.

Sources & Further Reading

All claims in this article are sourced from primary documentation, vendor advisories, and reputable security researchers.

Spotted an error? Email the editor. Corrections are issued with a visible correction note.

Editorial standards. Every article on humanrequired.org is reviewed by a human editor before publication. AI may assist with drafting or research; final editorial control is human. Read the full standards.

Continue reading