Skip to content
July 27, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • News
  • Technology
  • Zerodium Company Offers $500,000 to Buy Linux Zero-Day Vulnerabilities
  • Technology

Zerodium Company Offers $500,000 to Buy Linux Zero-Day Vulnerabilities

Do Son July 3, 2018 3 minutes read
Zerodium Linux Zero-Day Vulnerabilities
Add Daily CyberSecurity as a preferred source on Google

The acquisition and sale of zero-day vulnerabilities can be said to be a productive business, but many people often overlook it. To better understand its evolution, let us analyse the latest offer from Zerodium, a popular different vulnerability trading platform. Of course, to get a detailed understanding of the company’s operating model and business philosophy, we can directly access their website.

“ZERODIUM pays premium bounties and rewards to security researchers to acquire their original and previously unreported zero-day research affecting major operating systems, software, and devices.” reads the company web sites. “While the majority of existing bug bounty programs accept almost any kind of vulnerabilities and PoCs but pay very low rewards, at ZERODIUM we focus on high-risk vulnerabilities with fully functional exploits, and we pay the highest rewards on the market.”

Like other vulnerability trading platforms, Zerodium acquired zero-day vulnerabilities and sold them to government agencies and law enforcement agencies, but many privacy advocates fear that some surveillance companies may use these vulnerabilities to sell their products to authoritarian governments.

Zerodium offers up to $500,000 in acquisitions for zero-day vulnerabilities on UNIX-based operating systems, including OpenBSD, FreeBSD and NetBSD. The same amount of price is available for zero-day exploits for mainstream Linux distributions such as Ubuntu, CentOS, Debian, and Tails.

The price of a zero-day vulnerability varies by a number of factors, including the market share of the affected platform/system (Windows zero-day vulnerabilities are usually higher than the Linux zero-day vulnerabilities) and the level of user interaction required to exploit the weaknesses (eg , the number of times the user needs to click).

Other factors include the reliability of a zero-day attack, the number of other vulnerabilities that need to be exploited to exploit a weakness, the success rate, and the operating system configuration required to exploit the vulnerability.

Since February of this year, the price increase trend of Linux zero-day vulnerabilities have been maintained, and the purchase price at that time has reached as high as 45,000 US dollars. The company has already shared its latest acquisition plan, although the primary target is still for remote code execution or local privilege escalation vulnerabilities for Linux and BSD systems, the price range and the highest purchase price have been adjusted.

Zerodium’s current purchase price for zero-day vulnerabilities in Linux privilege ranges from $10,000 to $30,000, while the highest purchase price for local privilege escalation (LPE) vulnerabilities in Linux is as high as $100,000. The purchase price for Linux remote code execution vulnerabilities can range from $50,000 to $500,000, with CentOS and Ubuntu zero-day vulnerabilities being what they want most.

Get Zero-Hour Vulnerability Alerts

Critical CVEs, CVSS scores, and PoC updates — straight to your inbox every week.


We respect your inbox. Unsubscribe anytime.

Related coverage

  • The Ethics Embargo: Why the Pentagon Blacklisted Anthropic and the Tech Giants Struck Back
  • Google Gemini 3.5 Flash Introduces Computer Use Capabilities
  • Community Notes: Meta Invites All Users to Test New Fact-Checking System
  • The FCC’s Rollback of Broadband Transparency Rules
  • Transparency Restored: Apple’s Plan to Fix Liquid Glass in iOS 27 with a Systemwide Slider
Track all actively exploited CVEs →

Support Our Threat Intelligence

If you find our CVE report and cybersecurity news helpful, consider supporting our work.

Buy Me a Coffee Logo Buy Me a Coffee PayPal
Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Share this article:

Facebook Post LinkedIn Telegram
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: Linux Zero-Day Vulnerabilities Zerodium

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🚨 Active Exploits in the Wild

  • CVE-2026-16723CVSS 9.0
    A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson\'s stock...
    Admin intel📅 Updated: Jul 25, 2026
  • CVE-2026-16232CVSS 9.1
    An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain...
    CISA KEV📅 Added to KEV: Jul 22, 2026
  • CVE-2026-50522CVSS 9.8
    Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
    Admin intelCISA KEV📅 Added to KEV: Jul 22, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-63030CVSS 9.8
    WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion...
    Admin intelCISA KEV📅 Added to KEV: Jul 21, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-60137CVSS 5.9
    WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter...
    Admin intelCISA KEV📅 Added to KEV: Jul 21, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-0770CVSS 9.8
    Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers...
    CISA KEV📅 Added to KEV: Jul 21, 2026
  • CVE-2021-27137CVSS 8.1
    An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality...
    CISA KEV📅 Added to KEV: Jul 21, 2026
  • CVE-2026-6875CVSS 9.5
    ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability...
    Admin intel📅 Updated: Jul 18, 2026
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-64530CVSS 9.8
    In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_api:...
  • CVE-2026-66013CVSS 9.3
    OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the console registration...
  • CVE-2026-66012CVSS 10.0
    SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp...
  • CVE-2026-64523CVSS 9.8
    In the Linux kernel, the following vulnerability has been resolved: net/handshake: Take...
  • CVE-2026-64459CVSS 9.8
    In the Linux kernel, the following vulnerability has been resolved: tcp: restore...
  • CVE-2026-64450CVSS 9.1
    In the Linux kernel, the following vulnerability has been resolved: tipc: fix...
  • CVE-2026-64439CVSS 9.8
    In the Linux kernel, the following vulnerability has been resolved: crypto: krb5...
  • CVE-2026-64410CVSS 9.8
    In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable:...
  • CVE-2026-64399CVSS 9.8
    In the Linux kernel, the following vulnerability has been resolved: ksmbd: add...
  • CVE-2026-64397CVSS 9.8
    In the Linux kernel, the following vulnerability has been resolved: ksmbd: serialize...
Powered by CVE WATCHTOWER

Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Top Exploited CVEs
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • Disclaimer
    • DCMA
    • Privacy Policy
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • CVE Watchtower
    • CVE Statistics by Vendor 2026
    • Q2 2026 Report
    • Top Exploited CVEs
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.