Every piece of software you use has flaws nobody knows about yet. Some of those flaws are worth millions of dollars to the right buyer.
A zero-day is a vulnerability the software vendor does not know about, which means the vendor has had zero days to fix it. The vulnerability is the hidden flaw. The exploit is the code that weaponizes it. That distinction, used by IBM, CrowdStrike, and Acronis alike, is the key to understanding an entire underground economy.
When a zero-day exploit lands, there is usually no patch, no reliable antivirus signature, and often no clear sign anything went wrong. Google's Threat Intelligence Group counted 75 zero-days exploited in the wild in 2024, after 98 in 2023 and 63 in 2022. The numbers dipped, but the baseline stayed high. This is no longer an occasional crisis. It is a sustained pattern.
The three markets for a flaw
The zero-day trade is not one market. It is three, layered like an onion, each with different players and rules.
The white market is the legitimate one: bug bounty programs. Companies pay researchers to find flaws and report them so they can be patched. Everyone benefits, and the software gets safer one flaw at a time.
The gray market is murkier. Brokers buy vulnerabilities from researchers and sell them to government intelligence and law enforcement agencies, which keep them secret to use rather than fix. Companies like Zerodium, Crowdfense, and Exodus Intelligence operate here legally, acquiring exploits and selling them to state customers. Their published acquisition prices set the reference for the whole economy: $2.5 million for a full iOS exploit chain, $2.5 million for Android, $500,000 for a Chrome renderer exploit, and $200,000 for a Windows privilege escalation, according to 2026 research from the Reno Project's Ecosystem Dependency Project.
The black market is the criminal one. Russian-language forum operators broker exploit deals on venues including Exploit.in, XSS, and RAMP, with prices ranging from $5,000 to more than $10 million depending on the target and reliability. Buyers include ransomware affiliates and state-adjacent groups. Ransomware operations such as Cl0p have also acquired zero-days directly from researchers, bypassing open markets entirely and leaving no public trace of the transaction.
Why prices look like that
Enjoying this story?
Get the five most important stories in tech, every morning. Free.
Exploit prices track three things: how widely the target software is used, how hard the flaw is to find, and how reliable the exploit is. An iPhone exploit chain that works with zero clicks, no phishing link and no user interaction, commands the top of the market because it works against hundreds of millions of identical devices.
Brokers do more than match buyers and sellers. They verify the exploit actually works, protect identities on both sides, and take a cut of the transaction. An exploit is not a one-time information good like a stolen password. It is a software engineering project that must be maintained as vendors ship updates, which is part of why the prices rival the budgets of small countries.
A zero-day exploit is not a one-time secret. It is a software engineering project, maintained like any other, that happens to break into things.
What the numbers say about the threat
What a zero-day costs, by target
Published 2026 acquisition prices from government-facing exploit brokers; criminal market prices vary by target and reliability.
The statistics tell a story of acceleration. Mandiant's M-Trends 2025 report found that vulnerability exploitation accounted for 33 percent of intrusions investigated in 2024, the fifth straight year it was the top initial access vector. Attackers are not breaking in through clever phishing as often as they used to. They are walking through unlocked doors in the software itself.
The targets have shifted too. About 44 percent of exploited zero-days now hit enterprise products: VPNs, firewalls, network appliances, and file transfer tools. These sit on the internet's edge, directly reachable, and one compromised appliance can open a path into an entire corporate network. The MOVEit Transfer campaign of 2023 remains the textbook case: the Cl0p group exploited a single flaw, CVE-2023-34362, and Emsisoft tracking later tied the fallout to more than 2,700 organizations and data exposure affecting about 93 million people.
Speed is the other half of the story. Data cited from VulnCheck indicates roughly 32 percent of cases show exploitation on the same day as disclosure, or even before a patch is widely available. Defenders used to have weeks. Now they sometimes have hours.
And the buyers are diversifying. Google's threat researchers attributed nearly 30 percent of state-linked zero-day exploitation in 2024 to China-linked groups, but ransomware crews and criminal brokers buy, sell, and reuse the same exploit chains. A flaw discovered for espionage can end up encrypting a hospital.
The cases that made the market real

Stuxnet, first publicly analyzed in 2010, used multiple Windows zero-days and spread via USB drives to sabotage Iranian nuclear infrastructure. It proved that software flaws could cause physical destruction, and it remains the strongest example of a cyber operation with kinetic effects.
In early 2024, Ivanti's Connect Secure VPN appliances were hit through chained flaws, CVE-2023-46805 and CVE-2024-21887. The U.S. cybersecurity agency CISA issued Emergency Directive 24-01, a measure reserved for the most severe cases. Within days, researchers reported widespread compromise.
Late 2024 brought the same pattern to Cleo's managed file transfer products: internet-facing software, a serious flaw, fast abuse, and large downstream risk for customers moving sensitive files. The product categories change. The playbook does not.
What actually helps
There is no patch for an unknown flaw, so defense has shifted from prevention to resilience. Security teams lean on endpoint detection that watches behavior rather than signatures, since traditional antivirus often misses threats with no known fingerprint. They patch fast, because known flaws get chained with unknown ones. They segment networks to limit how far an intruder can move, and they keep threat intelligence feeds to catch related indicators sooner.
The unglamorous truth is that most zero-day damage is limited by basics done well: verified backups, tight identity controls, and a practiced incident response plan. In cybersecurity, the first hours still decide the outcome, and the organizations that survive zero-days are usually the ones that assumed they would eventually face one.
The market, meanwhile, is not going away. As long as software ships with flaws and governments, criminals, and brokers will pay for them, the trade will continue. The United States has begun treating exploit marketplaces as national security threats rather than purely criminal enterprises, including sanctions against brokers. But sanctions target the visible players. The market itself, distributed across forums, private chats, and direct deals, keeps growing faster than the rules meant to contain it.
0 Comments