Skip to content
June 12, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Watchtower
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Vulnerability Report
Light/Dark Button
  • Home
  • News
  • Technology
  • Zerodium Company Offers $500,000 to Buy Linux Zero-Day Vulnerabilities
  • Technology

Zerodium Company Offers $500,000 to Buy Linux Zero-Day Vulnerabilities

Do Son July 3, 2018 3 minutes read
Zerodium Linux Zero-Day Vulnerabilities
Add as a preferred
source on Google

The acquisition and sale of zero-day vulnerabilities can be said to be a productive business, but many people often overlook it.Β To better understand its evolution, let us analyse the latest offer from Zerodium, a popular different vulnerability trading platform.Β Of course, to get a detailed understanding of the company’s operating model and business philosophy, we can directly access their website.

“ZERODIUM pays premium bounties and rewards to security researchersΒ to acquire their original and previously unreported zero-day research affecting major operating systems, software, and devices.” readsΒ the companyΒ web sites. β€œWhile the majority of existing bug bounty programs accept almost any kind of vulnerabilities and PoCs but pay very low rewards,Β at ZERODIUM we focus on high-risk vulnerabilities with fully functional exploits, and we pay the highest rewards on the market.”

Like other vulnerability trading platforms, Zerodium acquired zero-day vulnerabilities and sold them to government agencies and law enforcement agencies, but many privacy advocates fear that some surveillance companies may use these vulnerabilities to sell their products to authoritarian governments.

Zerodium offers up to $500,000 in acquisitions for zero-day vulnerabilities on UNIX-based operating systems, including OpenBSD, FreeBSD and NetBSD.Β The same amount of price is available for zero-day exploits for mainstream Linux distributions such as Ubuntu, CentOS, Debian, and Tails.

The price of a zero-day vulnerability varies by a number of factors, including the market share of the affected platform/system (Windows zero-day vulnerabilities are usually higher than the Linux zero-day vulnerabilities) and the level of user interaction required to exploit the weaknesses (eg , the number of times the user needs to click).

Other factors include the reliability of a zero-day attack, the number of other vulnerabilities that need to be exploited to exploit a weakness, the success rate, and the operating system configuration required to exploit the vulnerability.

Since February of this year, the price increase trend of Linux zero-day vulnerabilities have been maintained, and the purchase price at that time has reached as high as 45,000 US dollars.Β The company has already shared its latest acquisition plan, although the primary target is still for remote code execution or local privilege escalation vulnerabilities for Linux and BSD systems, the price range and the highest purchase price have been adjusted.

Zerodium’s current purchase price for zero-day vulnerabilities in Linux privilege ranges from $10,000 to $30,000, while the highest purchase price for local privilege escalation (LPE) vulnerabilities in Linux is as high as $100,000.Β The purchase price for Linux remote code execution vulnerabilities can range from $50,000 to $500,000, with CentOS and Ubuntu zero-day vulnerabilities being what they want most.

Rate this post

Support Our Threat Intelligence

If you find our CVE report and cybersecurity news helpful, consider supporting our work.

Buy Me a Coffee Logo Buy Me a Coffee PayPal
Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Share this article:

Facebook Post LinkedIn Telegram

Related posts:

  1. Wine 3.0: Android phone can run Windows apps
  2. Canonical releases security kernel patch for Ubuntu 17.10 & Ubuntu 16.04 LTS (HWE)
  3. After 18 months, Nougat has finally become the most popular Android versions
  4. Chrome OS will supports .deb package installation
  5. Awe Dropping: Apple Announces September 9 Event, Teasing a Groundbreaking Design
Written by
@DdoS Β· Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: Linux Zero-Day Vulnerabilities Zerodium

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚑

Get notified instantly when a Proof of Concept (PoC) exploit is published.

πŸ”

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

πŸ“Š

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

πŸ”΄ Live Critical Threats

  • CVE-2026-6853CVSS 9.8
    Improper restriction of excessive authentication attempts vulnerability in Başbelen Group Food Cafe...
  • CVE-2026-54133CVSS 9.8
    jmespath.php allows users to use JMESPath, software for declaratively specifying how to...
  • CVE-2026-47210CVSS 9.8
    vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4,...
  • CVE-2026-47208CVSS 10.0
    vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4,...
  • CVE-2026-47137CVSS 10.0
    vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4,...
  • CVE-2026-47140CVSS 10.0
    vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4,...
  • CVE-2026-47131CVSS 10.0
    vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4,...
  • CVE-2026-50091CVSS 9.1
    Aqara Home Android (com.lumiunited.aqarahome) 6.0.0 (and white-label clients embedding the same liblumidevsdk.so)...
  • CVE-2026-50090CVSS 9.3
    The Aqara Cloud OAuth Authorization Endpoint (open-cn.aqara.com/oauth/authorize) is vulnerable to a redirect...
  • CVE-2026-50086CVSS 10.0
    The Aqara IAM/SSO gateway (gw-builder.aqara.com) exposes bidirectional AES round-trups against the platform's...
Powered by CVE WATCHTOWER

Recent Zero-Day Vulnerabilities

  • GreatXML BitLocker Bypass: Public PoC Exploit Disclosed
  • Check Point VPN Vulnerability Exploited in the Wild with Ransomware Links
  • Weekly Threat Intelligence: June 1 to June 7, 2026
  • Cisco SD-WAN Vulnerability Exploited in the Wild with Root RCE Risks
  • Android Zero-Day Flaw Exploited in the Wild: June 2026 Patches Released
  • Exploited in the Wild: Critical OWA Spoofing Flaw (CVE-2026-42897) Hits On-Premises Exchange Servers
Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • Disclaimer
    • Privacy Policy
    • DMCA NOTICE
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    Β© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.