Join our Newsletter — 33% off our NHI Course
Threats, Abuse & Incident Response

Exploit Broker

← Back to Glossary
By NHI Mgmt Group Updated September 28, 2026 Domain: Threats, Abuse & Incident Response

An exploit broker is an intermediary that buys and sells exploit capabilities, often matching researchers, criminal buyers, and state-aligned buyers in opaque markets. The broker adds liquidity to a market that lacks public pricing, making it harder for defenders to understand demand, value, and likely threat activity.

What an exploit broker does

An exploit broker is not the same as a vulnerability researcher or a simple reseller. The broker sits between supply and demand, turning exploit capabilities into a tradable commodity and often obscuring who ultimately receives the capability.

That intermediary role matters because it changes how exploit value is discovered, packaged, and exchanged. The broker may aggregate proof-of-concept code, working chains, access, or weaponised exploits, then present them to buyers who want speed, discretion, or a specific target fit.

How exploit brokering changes the market

Exploit brokering adds liquidity to a market that is usually fragmented and opaque. Instead of one-off direct deals, brokers can create repeatable channels where researchers, criminal groups, and state-aligned buyers transact through intermediated relationships.

This can widen the reach of a single exploit capability. A broker may not write the exploit, but by finding the right buyer and sometimes the right disclosure timing, the broker can determine whether the capability is used for responsible remediation, espionage, extortion, or broader criminal access.

Why brokers are strategically important

For defenders, the broker matters because it signals demand. If a broker is active around a product class, feature, or exploitation technique, that often suggests the underlying capability has market value and may be operationally useful to multiple threat groups.

Exploit brokering can also shorten the time between discovery and real-world abuse. Public visibility into pricing and ownership is limited, so a broker can help normalise a private market in which the same capability is repurposed across campaigns. Research and incident tracking that capture real exploitation patterns, such as The 52 NHI Breaches Report, are useful for understanding how quickly valuable capabilities tend to move once they become operationally attractive.

What the term means for security teams

Exploit brokering is a reminder that defenders are not only facing isolated attackers, they are facing a market. When exploit supply becomes brokered, security teams should think in terms of demand signals, likely buyer profiles, and the commercial value of a given weakness rather than treating every exploit as a one-off event.

That is why exploitability, active exploitation, and exposure prioritisation matter. A capability that is easy to weaponise, easy to resell, or useful against a widely deployed product can spread quickly once a broker can move it through the right channels. Sources that track active exploitation and prioritisation, such as CISA Known Exploited Vulnerabilities Catalog and FIRST EPSS, help frame that market pressure more realistically than raw vulnerability counts alone.

Risk and Threat Considerations

Exploit brokers increase the risk that a newly discovered weakness becomes monetised before defenders can respond. They also make it easier for multiple buyers to obtain the same capability, which can accelerate exploitation, broaden targeting, and reduce the chance that a single disclosure cycle contains the damage.

Failure mechanism: A broker concentrates access to weaponised capability, then matches it to buyers who value speed, stealth, or target specificity. That market structure can preserve exploit secrets, hide buyer intent, and keep dangerous chains circulating after defenders believe a patch window has closed.

Impact: Organisations may face faster exploitation, wider campaign repetition, and more uncertainty about who can access a working exploit. The result is a harder prioritisation problem for patching, exposure management, and threat hunting, especially when the exploit is already present in active vulnerability catalogs or exploitation intelligence feeds.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack and risk surface, while CIS Controls v8, NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
MITRE ATT&CKT1588.005 — Exploit DevelopmentExploit brokering depends on monetised exploit capability as an attacker resource.
T1595 — Active ScanningBrokered exploits often follow exposure discovery and target selection before use.
Recommendation — Track exploit acquisition patterns as attacker capability development and prioritise exposed systems accordingly. Correlate scan activity with vulnerable assets to detect likely brokered-exploit targeting.
CIS Controls v8CIS-7 — Continuous Vulnerability ManagementExploit brokers raise the value of rapidly exploitable weaknesses that need continuous prioritisation.
Recommendation — Prioritise remediation based on exploitability and active threat use, not just CVSS.
NIST SP 800-53 Rev 5RA-5 — Vulnerability Monitoring and ScanningBrokered exploits make timely vulnerability discovery and response materially more urgent.
Recommendation — Continuously monitor exposed assets and rapidly act on vulnerabilities with likely exploitation paths.
NIST CSF 2.0ID.RA-01 — Vulnerabilities are identified and documentedExploit brokerage changes which vulnerabilities become strategically important to document and track.
Recommendation — Document exploitable weaknesses and tie them to threat intelligence for prioritisation.

Practitioner Guidance

Why practitioners should care: Treat exploit-broker activity as a demand indicator, not just a criminal trade curiosity. When a broker appears around a product or technique, it is often a sign that the capability is valuable enough to be operationalised by more than one threat actor.

What to watch for: Prioritise weaknesses that are both exploitable and marketable, especially those with public proof-of-concept code, clear remote execution paths, or confirmed active exploitation. Practitioner triage is stronger when it combines exploitability data, exposure data, and active-threat reporting rather than relying on severity scores alone.

Practitioner takeaway: A brokered exploit market means your response window is governed as much by attacker economics as by technical severity.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 28, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org